VendorsAgentejocockpitany version
Vulnerabilities

Agentejo Cockpit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2023-4195
PHP Remote File Inclusion in cockpit-hq/cockpit
Published 2023-08-06 · Modified
9.9EPSS 0.011
CVE-2020-35847
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Published 2020-12-30 · Modified
9.81 PoCEPSS 0.982
CVE-2020-35846
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Published 2020-12-30 · Modified
9.8EPSS 0.933
CVE-2020-35848
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Published 2020-12-30 · Modified
9.81 PoCEPSS 0.746
CVE-2020-35131
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
Published 2021-01-08 · Modified
9.8EPSS 0.513
CVE-2018-15540
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
Published 2018-10-15 · Modified
9.8EPSS 0.023
CVE-2022-2818
Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit
Published 2022-08-15 · Modified
9.8EPSS 0.017
CVE-2022-2713
Insufficient Session Expiration in cockpit-hq/cockpit
Published 2022-08-08 · Modified
9.8EPSS 0.012
CVE-2023-1313
Unrestricted Upload of File with Dangerous Type in cockpit-hq/cockpit
Published 2023-03-10 · Modified
8.8EPSS 0.010
CVE-2018-15539
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
Published 2018-10-15 · Modified
8.8EPSS 0.006
CVE-2023-37650
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
Published 2023-07-20 · Modified
8.8EPSS 0.005
CVE-2023-0759
Privilege Chaining in cockpit-hq/cockpit
Published 2023-02-09 · Modified
8.8EPSS 0.003
CVE-2023-4321
Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published 2023-08-14 · Modified
8.3EPSS 0.006
CVE-2023-4432
Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
Published 2023-08-19 · Modified
8.3EPSS 0.006
CVE-2023-4433
Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published 2023-08-19 · Modified
8.3EPSS 0.006
CVE-2023-4196
Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published 2023-08-06 · Modified
8.3EPSS 0.005
CVE-2023-4395
Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published 2023-08-17 · Modified
8.1EPSS 0.006
CVE-2026-31891
Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()
Published 2026-03-18 · Analyzed
7.7EPSS 0.004
CVE-2023-37649
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
Published 2023-07-20 · Modified
7.5EPSS 0.009
CVE-2023-4422
Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published 2023-08-18 · Modified
6.8EPSS 0.006
CVE-2023-4451
Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
Published 2023-08-20 · Modified
6.1EPSS 0.025
CVE-2018-15538
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
Published 2018-10-15 · Modified
6.1EPSS 0.008
CVE-2021-32857
Cockpit vulnerable to Cross-site Scripting
Published 2023-02-20 · Modified
6.1EPSS 0.007
CVE-2025-7053
Cockpit save cross site scripting
Published 2025-07-04 · Analyzed
6.1EPSS 0.003
CVE-2023-1160
Use of Platform-Dependent Third Party Components in cockpit-hq/cockpit
Published 2023-03-03 · Modified
5.5EPSS 0.003
CVE-2023-0780
Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit
Published 2023-02-11 · Modified
5.4EPSS 0.004