Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

panel — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in panel, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities affecting the "panel" product. It collects security advisories, patch notes, and related weakness classifications associated with this specific software component. The collection covers documented flaws ranging from low-severity configuration issues to critical remote code execution risks. Users can track the vendor's official security advisories, analyze the distribution of vulnerability types, and review the complete vulnerability history for this product. The data is organized by severity, affected version, and disclosure date, allowing analysts to identify patterns in fix timelines and recurring weakness classes.

Vendor: pterodactyl

CVE ID Title CVSS Severity Published
CVE-2026-92762 Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup CWE-862 8.8 High 2026-09-16
CVE-2026-86177 Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks CWE-862 8.8 High 2026-09-05
CVE-2026-61609 Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS) CWE-770 7.5 High 2026-07-28
CVE-2026-54593 Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions CWE-1259 8.1 High 2026-07-28
CVE-2026-35202 Pterodactyl has a database resource limit bypass via race condition in Client API CWE-367 - - 2026-06-02
CVE-2026-34358 CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass CWE-284 8.1 High 2026-05-19
CVE-2026-34246 CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output CWE-80 4.8 Medium 2026-05-19
CVE-2026-34241 CtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session Hijacking CWE-79 8.7 High 2026-05-19
CVE-2026-34234 CtrlPanel: Unauthenticated RCE using installer script CWE-78 10.0 Critical 2026-05-19
CVE-2026-34233 CtrlPanel has Missing Authentication Checks in Datatable Admin Endpoints CWE-284 6.5 Medium 2026-05-19
CVE-2026-34216 CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php CWE-470 6.6 Medium 2026-05-19
CVE-2026-33746 Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users CWE-287 9.8 Critical 2026-04-02
CVE-2026-5332 Xiaopi Panel WAF Firewall demo.php cross site scripting CWE-79 3.5 Low 2026-04-02
CVE-2026-34456 Reviactyl: OAuth account takeover via auto-linking CWE-284 9.1 Critical 2026-04-01
CVE-2026-26016 Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization CWE-639 8.1 - 2026-02-19
CVE-2026-2122 Xiaopi Panel WAF Firewall demo.php sql injection CWE-89 6.3 Medium 2026-02-08
CVE-2025-69199 Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances CWE-400 7.5AI High AI 2026-01-19
CVE-2025-69198 Pterodactyl's improper resource locking allows raced queries to create more resources than alloted CWE-400 6.5AI Medium AI 2026-01-19
CVE-2025-69197 Pterodactyl TOTPs can be reused during validity window CWE-287 6.5 Medium 2026-01-06
CVE-2025-68954 Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced CWE-613 6.5 - 2026-01-06
CVE-2025-53534 RatPanel can perform remote command execution without authorization CWE-305 9.8AI Critical AI 2025-08-05
CVE-2025-52562 Convey Panel Directory Traversal in LocaleController leading to Remote Code Execution CWE-22 10.0 Critical 2025-06-23
CVE-2025-49132 Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution CWE-94 10.0 Critical 2025-06-20
CVE-2025-25203 Ctrlpanel has stored XSS vulnerability in TicketsController priority field CWE-79 8.1 High 2025-02-11
CVE-2024-49762 Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled CWE-313 4.6 Medium 2024-10-24
CVE-2024-6878 Directory Browsing in Eliz Software's Panel CWE-552 6.5AI Medium AI 2024-09-18
CVE-2024-6877 Reflected XSS in Eliz Software's Panel CWE-79 6.1AI Medium AI 2024-09-18
CVE-2024-5960 Plaintext Storage of a Password in Eliz Software's Panel CWE-256 9.8 Critical 2024-09-18
CVE-2024-5959 Stored XSS in Eliz Software's Panel CWE-79 5.4AI Medium AI 2024-09-18
CVE-2024-5958 SQLi in Eliz Software's Panel CWE-89 9.8AI Critical AI 2024-09-18

All 34 known CVE vulnerabilities affecting panel with full Chinese analysis, references, and POCs where available.