Usmannasir Cyberpanel vulnerabilities
2 known vulnerabilities affecting usmannasir/cyberpanel.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-41473P2CRITICALCVSS 9.1fixed in 2.4.42026-04-24
CVE-2026-41473 [CRITICAL] CWE-306 CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authenticati
nvd
CVE-2026-41472P3MEDIUMCVSS 6.1fixed in 2.4.42026-04-24
CVE-2026-41472 [MEDIUM] CWE-79 CVE-2026-41472: CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Sca
CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that
nvd