Search
Search Results (14 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101011 | 1 Aapanel | 1 Baota | 2026-09-28 | 4.7 Medium |
| A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101008 | 1 Aapanel | 1 Baota | 2026-09-28 | 9.1 Critical |
| A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101010 | 1 Aapanel | 1 Baota | 2026-09-28 | 4.7 Medium |
| A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101007 | 1 Aapanel | 1 Baota | 2026-09-28 | 8.4 High |
| A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101009 | 1 Aapanel | 1 Baota | 2026-09-28 | 8.4 High |
| A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2025-12914 | 1 Aapanel | 1 Baota | 2026-04-15 | 4.7 Medium |
| A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.3.0 is able to resolve this issue. It is recommended to upgrade the affected component. | ||||
| CVE-2026-29856 | 1 Aapanel | 1 Aapanel | 2026-03-24 | 7.5 High |
| An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input. | ||||
| CVE-2026-29858 | 1 Aapanel | 1 Aapanel | 2026-03-24 | 7.5 High |
| A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure. | ||||
| CVE-2026-29859 | 1 Aapanel | 1 Aapanel | 2026-03-24 | 9.8 Critical |
| An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||||
| CVE-2024-42922 | 1 Aapanel | 1 Aapanel | 2025-06-25 | 6.5 Medium |
| AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. | ||||
| CVE-2022-26252 | 1 Aapanel | 1 Aapanel | 2024-11-21 | 6.5 Medium |
| aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa). | ||||
| CVE-2021-37840 | 1 Aapanel | 1 Aapanel | 2024-11-21 | 8.8 High |
| aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome). | ||||
| CVE-2020-14950 | 1 Aapanel | 1 Aapanel | 2024-11-21 | 8.8 High |
| aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAdmin request (start, stop, or restart) to the setting menu of Sotfware Store. | ||||
| CVE-2020-14421 | 1 Aapanel | 1 Aapanel | 2024-11-21 | 7.2 High |
| aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen. | ||||
Page 1 of 1.