Agentejo

Cockpit

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 18.03.2026 02:58:12
  • Zuletzt bearbeitet 20.03.2026 18:00:37

Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment wher...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 04.07.2025 02:02:05
  • Zuletzt bearbeitet 01.10.2025 13:56:03

A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may ...

  • EPSS 0.08%
  • Veröffentlicht 14.05.2024 15:45:16
  • Zuletzt bearbeitet 27.06.2025 15:04:13

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

  • EPSS 0.09%
  • Veröffentlicht 29.02.2024 14:15:45
  • Zuletzt bearbeitet 04.03.2025 12:25:10

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

  • EPSS 20.14%
  • Veröffentlicht 08.09.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 08:21:18

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

Exploit
  • EPSS 63.61%
  • Veröffentlicht 20.08.2023 15:15:29
  • Zuletzt bearbeitet 13.02.2026 17:16:09

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 19.08.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:08

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 19.08.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:08

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 18.08.2023 19:15:13
  • Zuletzt bearbeitet 21.11.2024 08:35:06

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 17.08.2023 04:15:10
  • Zuletzt bearbeitet 21.11.2024 08:35:03

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.