Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

portainer — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting portainer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerability data for the container management platform Portainer, focusing on common weakness types such as cross-site scripting, authentication bypass, and insecure direct object references. The database compiles known security issues affecting various versions of Portainer and its associated components, covering a historical range from early releases through the most recent updates to ensure comprehensive visibility into the product's security posture. Here, users can track vendor advisories to stay informed about critical patches and security bulletins, gain a deeper understanding of specific weakness classes prevalent in container orchestration tools, and look up a product’s detailed vulnerability history to assess risk over time. This resource is designed to assist security analysts, DevOps engineers, and system administrators in maintaining a secure infrastructure by providing clear, structured information about identified defects and their resolutions. By centralizing this data, the page facilitates proactive vulnerability management and helps organizations prioritize remediation efforts based on the severity and context of each reported issue. The information presented is derived from official vendor notifications, public databases, and verified security research, ensuring accuracy and reliability for decision-making processes.

Found 10 results / 12Clear Filters
Critical2026-07-09
Unauthenticated Restore and Admin-Account-Creation Endpoints Allow Admin Takeover on Uninitialised Portainer Instances ·
Unknown2026-07-09
Release Release 2.39.4 LTS · portainer/portainer · GitHub
High2026-07-09
Release Release 2.43.0 STS · portainer/portainer · GitHub
Medium2026-05-29
Path traversal in backup archive extraction allows arbitrary file write · Advisory · portainer/portainer · GitHub
HighCVE-2025-448502026-05-29
Bind-mount restriction bypass via HostConfig.Mounts · Advisory · portainer/portainer · GitHub
HighCVE-2020-448812026-05-29
Arbitrary File Read via Git Symlink Injection in Stack Auto-Update · Advisory · portainer/portainer · GitHub
High2026-05-29
Kubernetes middleware continues after token validation failure, bypassing endpoint authorization · Advisory · portainer/
MediumCVE-2025-448842026-05-29
Missing authorization on custom template file endpoint exposes template content · Advisory · portainer/portainer · GitHu
High2026-05-29
JWT accepted in URL query leaks tokens to logs and referers · Advisory · portainer/portainer · GitHub
Critical2026-05-29
Missing authorization on Docker plugin endpoints allows host RCE · Advisory · portainer/portainer · GitHub
Critical2026-05-29
Endpoint security bypass via Swarm service create/update · Advisory · portainer/portainer · GitHub
Unknown2026-05-29
fix(environments): improve the default environment security settings … · portainer/portainer@ac8fa76 · GitHub
High2026-05-29
fix(swarm): fix environment security checks BE-12541 (#1666) · portainer/portainer@3e2fdb1 · GitHub
MediumCVE-2025-495932025-07-06
HTTP Headers May Leak to Malicious Container Registries · Advisory · portainer/portainer · GitHub
Unknown2025-07-06
fix(proxy): whitelist headers for proxy to forward [BE-11819] (#665) · portainer/portainer@b767dcb · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with portainer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.