Mgt Commerce maintains CloudPanel, a focused web hosting control-panel product whose vulnerability disclosures, while modest in scope, reflect the integration and access-control demands of a platform that sits between administrators and underlying infrastructure. The recurring exposure centers on the product's administrative interface and authentication model rather than a single dominant weakness class. Defenders should prioritize this vendor's updates where CloudPanel is deployed as a management layer for customer-facing hosting environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mgt Commerce over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35885CRITICAL CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | Jun 20, 2023 | 9.8 | 81 | NO | YES |
CVE-2023-36630HIGH In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass. | Jun 25, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-24320HIGH Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the servic | Jun 14, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-0391HIGH MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior | Mar 21, 2023 | 8.1 | 25 | NO | NO |
CVE-2023-46157HIGH File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755 | Dec 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-33747HIGH CloudPanel v2.2.2 allows attackers to execute a path traversal. | Jun 6, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mgt Commerce.
Media articles that mention a CVE ID that affects a product developed by Mgt Commerce — matched by CVE ID, not by vendor name.