Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fit2cloud

First CVE: Jan 13, 2022Active for: 5 yearsTotal CVEs: 77
59.4
VTI Score
TOP TARGET

Fit2cloud's vulnerability footprint spans a modestly sized but well-represented portfolio of infrastructure and management platforms, including JumpServer (privileged-access management), 1Panel (server management), CloudExplorer Lite (cloud resource inventory), KubePI (Kubernetes operations), and SqlBot (database tools), each deployed across organizations managing on-premises and cloud environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of the products' administrative and control-plane roles. The exposure recurs persistently through authorization and input-handling defects, particularly missing authorization checks, command injection, SQL injection, and cross-site scripting, which are characteristic weaknesses in web-facing management interfaces where the attack surface directly touches sensitive infrastructure operations. Defenders should treat Fit2cloud advisories as high-priority for any deployed instances, prioritize internet-reachable exposure of these platforms, and inventory affected versions across their operational and cloud-management tiers. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
77
Total CVEs
More Total CVEs than 99% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fit2cloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2022
4 years ago
Most Recent CVE
May 13, 2026
72 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (77 CVEs).

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-22463CRITICAL
KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This me
Jan 4, 20239.879NOYES
CVE-2023-22480CRITICAL
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and be
Jan 14, 20239.877NOYES
CVE-2024-39907CRITICAL
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes,
Jul 18, 20249.859NOYES
CVE-2023-42442MEDIUM
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, sessi
Sep 15, 20235.352NOYES
CVE-2025-54424CRITICAL
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for c
Aug 1, 20259.835NONO
CVE-2023-22478HIGH
KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are curre
Jan 14, 20237.535NOYES
CVE-2026-33324HIGH
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. Th
May 5, 20268.834NONO
CVE-2024-29202CRITICAL
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's An
Mar 29, 20249.934NONO
CVE-2025-58044MEDIUM
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header a
Dec 1, 20256.133NOYES
CVE-2024-29201CRITICAL
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to exe
Mar 29, 20249.933NONO
View all 77 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products77 CVEs
35%
36%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.3%)
Network76 (98.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (90.9%)
High7 (9.1%)
Unknown0 (0.0%)
User Interaction
None62 (80.5%)
Unknown0 (0.0%)
Required15 (19.5%)
Privileges Required
Low29 (37.7%)
High5 (6.5%)
None43 (55.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (77 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
7 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fit2cloud.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fit2cloud — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fit2cloud's Products

View all 6 CNAs →

Top CWEs