Vulnerabilities in Ctrlpanel-gg
7 resultsVexday analysis
Ctrlpanel-gg apresenta 7 vulnerabilidades catalogadas, com 6 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta. Não há evidências de exploração ativa em campo (zero entradas em KEV), mas 1 falha crítica foi identificada, concentrando-se predominantemente em problemas de controle de acesso (CWE-284). O padrão de descobertas recentes merece monitoramento contínuo, embora o risco imediato de ataque seja contido.
CVE-2026-34234CRITICALCtrlPanel: Unauthenticated RCE using installer scriptEPSS 0.8%CVE-2026-34216MEDIUMCtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phpEPSS 0.5%CVE-2025-25203HIGHCtrlpanel has stored XSS vulnerability in TicketsController priority fieldEPSS 0.4%CVE-2026-34241HIGHCtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session HijackingEPSS 0.3%CVE-2026-34358HIGHCtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC BypassEPSS 0.3%CVE-2026-34233MEDIUMCtrlPanel has Missing Authentication Checks in Datatable Admin EndpointsEPSS 0.3%CVE-2026-34246MEDIUMCtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML OutputEPSS 0.2%