Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

panel — Vulnerabilities & Security Advisories 32

All 32 CVE vulnerabilities found in panel, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of vulnerabilities affecting the Panel product, covering various weakness types and associated security tags. It collects security incidents ranging from critical remote code execution flaws to information disclosure and authentication bypass issues, with data spanning from early development stages through to recent stable releases. Visitors can track the vendor’s security advisories to understand the response timeline and patch availability for reported issues. Users may also examine specific weakness classes to identify common attack vectors and mitigation strategies relevant to this software environment. Additionally, the page allows for a detailed look up of the product’s vulnerability history, enabling security teams to assess the overall risk posture and prioritize updates based on severity and exploitability. By consolidating these data points, the resource aims to simplify the process of monitoring the security landscape for the Panel product. It serves as a central reference for administrators and developers seeking to maintain system integrity by staying informed about known defects and their corresponding fixes. The structured presentation facilitates quick identification of high-risk areas without requiring extensive manual searching across disparate sources.

Vendor: pterodactyl

CVE ID Title CVSS Severity Published
CVE-2026-61609 Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS) CWE-770 7.5 High 2026-07-28
CVE-2026-54593 Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions CWE-1259 8.1 High 2026-07-28
CVE-2026-35202 Pterodactyl has a database resource limit bypass via race condition in Client API CWE-367 - - 2026-06-02
CVE-2026-34358 CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass CWE-284 8.1 High 2026-05-19
CVE-2026-34246 CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output CWE-80 4.8 Medium 2026-05-19
CVE-2026-34241 CtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session Hijacking CWE-79 8.7 High 2026-05-19
CVE-2026-34234 CtrlPanel: Unauthenticated RCE using installer script CWE-78 10.0 Critical 2026-05-19
CVE-2026-34233 CtrlPanel has Missing Authentication Checks in Datatable Admin Endpoints CWE-284 6.5 Medium 2026-05-19
CVE-2026-34216 CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php CWE-470 6.6 Medium 2026-05-19
CVE-2026-33746 Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users CWE-287 9.8 Critical 2026-04-02
CVE-2026-5332 Xiaopi Panel WAF Firewall demo.php cross site scripting CWE-79 3.5 Low 2026-04-02
CVE-2026-34456 Reviactyl: OAuth account takeover via auto-linking CWE-284 9.1 Critical 2026-04-01
CVE-2026-26016 Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization CWE-639 8.1 - 2026-02-19
CVE-2026-2122 Xiaopi Panel WAF Firewall demo.php sql injection CWE-89 6.3 Medium 2026-02-08
CVE-2025-69199 Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances CWE-400 7.5AI High AI 2026-01-19
CVE-2025-69198 Pterodactyl's improper resource locking allows raced queries to create more resources than alloted CWE-400 6.5AI Medium AI 2026-01-19
CVE-2025-69197 Pterodactyl TOTPs can be reused during validity window CWE-287 6.5 Medium 2026-01-06
CVE-2025-68954 Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced CWE-613 6.5 - 2026-01-06
CVE-2025-53534 RatPanel can perform remote command execution without authorization CWE-305 9.8AI Critical AI 2025-08-05
CVE-2025-52562 Convey Panel Directory Traversal in LocaleController leading to Remote Code Execution CWE-22 10.0 Critical 2025-06-23
CVE-2025-49132 Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution CWE-94 10.0 Critical 2025-06-20
CVE-2025-25203 Ctrlpanel has stored XSS vulnerability in TicketsController priority field CWE-79 8.1 High 2025-02-11
CVE-2024-49762 Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled CWE-313 4.6 Medium 2024-10-24
CVE-2024-6878 Directory Browsing in Eliz Software's Panel CWE-552 6.5AI Medium AI 2024-09-18
CVE-2024-6877 Reflected XSS in Eliz Software's Panel CWE-79 6.1AI Medium AI 2024-09-18
CVE-2024-5960 Plaintext Storage of a Password in Eliz Software's Panel CWE-256 9.8 Critical 2024-09-18
CVE-2024-5959 Stored XSS in Eliz Software's Panel CWE-79 5.4AI Medium AI 2024-09-18
CVE-2024-5958 SQLi in Eliz Software's Panel CWE-89 9.8AI Critical AI 2024-09-18
CVE-2024-34067 Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel CWE-79 6.1 Medium 2024-05-03
CVE-2021-41273 Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys CWE-352 4.3 Medium 2021-11-17

All 32 known CVE vulnerabilities affecting panel with full Chinese analysis, references, and POCs where available.