Panel Vulnerabilities

pip ML UI

AI Threat Alert tracks 55 known vulnerabilities in Panel, 16 rated critical — an AI/ML ml ui in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
26
Risk Score
55
Total CVEs
16
Critical
pip
Ecosystem
Aug 6, 2026
Last CVE
61%
Patch Rate
16d
Avg Time to Patch
5,731 stars 620 forks 1,112 issues 499 dependents Last push Aug 14, 2026
View on GitHub
OpenSSF Scorecard 6.8/10

Known Vulnerabilities (53 total, page 1 of 3)

Severity CVE ID Summary CVSS Published
HIGH CVE-2025-30033 The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component. 7.8 Aug 12, 2025 MEDIUM GHSA-xxpx-f366-4xpq Craft CMS: view-only role can restructure categories -- Aug 6, 2026 MEDIUM CVE-2026-18766 A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no ve 6.3 Aug 4, 2026 CRITICAL CVE-2026-52855 Pterodactyl Wings: egg template leaks daemon secrets 9.9 Jul 31, 2026 HIGH CVE-2026-61609 Pterodactyl Panel: global rate limiter enables panel-wide login DoS 7.5 Jul 28, 2026 HIGH CVE-2026-54593 Pterodactyl Wings: JWT reuse enables file upload bypass 8.1 Jul 28, 2026 HIGH CVE-2021-47816 Thecus NAS: authenticated command injection to RCE 8.8 Jan 16, 2026 MEDIUM CVE-2026-54497 ViewComponent: stale context leaks admin UI cross-user 6.8 Jul 15, 2026 HIGH CVE-2026-45414 Decidim: JWT replay bypasses multi-tenant isolation 8.5 Jul 13, 2026 HIGH CVE-2026-54070 SiYuan: XSS in Bazaar README steals admin API token 7.1 Jul 10, 2026 MEDIUM CVE-2026-9557 Mautic Focus: SSRF enables internal network recon 6.4 Jul 2, 2026 MEDIUM GHSA-j7f5-gfqm-pcx3 Pterodactyl panel: email endpoint leaks user enumeration -- Jun 26, 2026 CRITICAL CVE-2026-54158 SiYuan: XSS→RCE via workspace sync in Electron app 9.9 Jun 24, 2026 MEDIUM GHSA-7cqp-7cfv-6c3q AVideo Meet: Stored XSS via User-Agent → admin takeover -- Jun 23, 2026 CRITICAL CVE-2018-25117 VestaCP: backdoored installer, not an AI/ML CVE -- Oct 15, 2025 MEDIUM CVE-2026-48500 Filament: unauth file upload drains disk/inflates costs 6.5 Jun 22, 2026 HIGH CVE-2026-54317 Home Assistant Konnected: auth bypass leaks alarm panel state 7.6 Jun 19, 2026 MEDIUM CVE-2026-49274 Kirby CMS: missing auth exposes restricted page titles -- Jun 18, 2026 HIGH CVE-2026-49276 Kirby CMS: XSS via writer field malicious links -- Jun 18, 2026 MEDIUM CVE-2026-50188 Kirby CMS: CRLF injection overrides outbound HTTP headers -- Jun 18, 2026 HIGH CVE-2026-54002 Kirby CMS: stored XSS bypasses DOM sanitizer via unwrap flaw -- Jun 18, 2026 UNKNOWN CVE-2026-54003 Kirby CMS: admin takeover via reverse proxy header bypass -- Jun 18, 2026 HIGH CVE-2025-0616 Netsis Panel: unauthenticated SQLi enables data exfiltration 8.2 Oct 3, 2025 MEDIUM CVE-2025-7014 Menu Panel: session fixation enables session hijacking 5.7 Jan 29, 2026 MEDIUM CVE-2025-7013 Menu Panel: IDOR auth bypass exposes confidential data 5.7 Jan 29, 2026

Showing 1–25 of 53

Frequently asked questions

What is Panel?

Panel is an AI/ML ml ui tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Panel have?

Panel has 55 known CVEs, 16 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Panel distributed in?

Panel is distributed via the pip ecosystem and categorized as ml ui.

Where does the Panel vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Panel?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Panel in your stack

Get instant alerts when new vulnerabilities affect Panel. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring