Fit2cloud's vulnerability footprint spans a modestly sized but well-represented portfolio of infrastructure and management platforms, including JumpServer (privileged-access management), 1Panel (server management), CloudExplorer Lite (cloud resource inventory), KubePI (Kubernetes operations), and SqlBot (database tools), each deployed across organizations managing on-premises and cloud environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of the products' administrative and control-plane roles. The exposure recurs persistently through authorization and input-handling defects, particularly missing authorization checks, command injection, SQL injection, and cross-site scripting, which are characteristic weaknesses in web-facing management interfaces where the attack surface directly touches sensitive infrastructure operations. Defenders should treat Fit2cloud advisories as high-priority for any deployed instances, prioritize internet-reachable exposure of these platforms, and inventory affected versions across their operational and cloud-management tiers. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fit2cloud over time
Signals from CVEs in this vendor scope (77 CVEs).
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22463CRITICAL KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This me | Jan 4, 2023 | 9.8 | 79 | NO | YES |
CVE-2023-22480CRITICAL KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and be | Jan 14, 2023 | 9.8 | 77 | NO | YES |
CVE-2024-39907CRITICAL 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, | Jul 18, 2024 | 9.8 | 59 | NO | YES |
CVE-2023-42442MEDIUM JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, sessi | Sep 15, 2023 | 5.3 | 52 | NO | YES |
CVE-2025-54424CRITICAL 1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for c | Aug 1, 2025 | 9.8 | 35 | NO | NO |
CVE-2023-22478HIGH KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are curre | Jan 14, 2023 | 7.5 | 35 | NO | YES |
CVE-2026-33324HIGH SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. Th | May 5, 2026 | 8.8 | 34 | NO | NO |
CVE-2024-29202CRITICAL JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's An | Mar 29, 2024 | 9.9 | 34 | NO | NO |
CVE-2025-58044MEDIUM JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header a | Dec 1, 2025 | 6.1 | 33 | NO | YES |
CVE-2024-29201CRITICAL JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to exe | Mar 29, 2024 | 9.9 | 33 | NO | NO |
Signals from CVEs in this vendor scope (77 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fit2cloud.
Media articles that mention a CVE ID that affects a product developed by Fit2cloud — matched by CVE ID, not by vendor name.