cbcvebase.

Aapanel Baota vulnerabilities

6 known vulnerabilities affecting aapanel/baota.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-101008P2CRITICALCVSS 9.1v11.0v11.1+7 more2026-09-28
CVE-2026-101008 [CRITICAL] CWE-74 CVE-2026-101008: A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file o A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made pu
nvd
CVE-2026-101007P2HIGHCVSS 8.4v11.0v11.1+7 more2026-09-28
CVE-2026-101007 [HIGH] CWE-77 CVE-2026-101007: A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputS A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2026-101009P3HIGHCVSS 8.4v11.0v11.1+7 more2026-09-28
CVE-2026-101009 [HIGH] CWE-77 CVE-2026-101009: A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function p A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been p
nvd
CVE-2026-101010P4MEDIUMCVSS 4.7v11.0v11.1+7 more2026-09-28
CVE-2026-101010 [MEDIUM] CWE-74 CVE-2026-101010: A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function g A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early
nvd
CVE-2026-101011P4MEDIUMCVSS 4.7v11.0v11.1+7 more2026-09-28
CVE-2026-101011 [MEDIUM] CWE-74 CVE-2026-101011: A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_dom A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to th
nvd
CVE-2025-12914P4MEDIUMCVSS 4.7v11.0v11.1+1 more2025-11-08
CVE-2025-12914 [MEDIUM] CWE-74 CVE-2025-12914: A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown cod A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to ve
nvd
Aapanel Baota vulnerabilities | cvebase