Panel Vulnerabilities

pip ML UI

AI Threat Alert tracks 76 known vulnerabilities in Panel, 20 rated critical — an AI/ML ml ui in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
26
Risk Score
76
Total CVEs
20
Critical
pip
Ecosystem
Sep 23, 2026
Last CVE
68%
Patch Rate
15d
Avg Time to Patch
5,777 stars 626 forks 1,109 issues 505 dependents Last push Sep 26, 2026
View on GitHub
OpenSSF Scorecard 6.8/10

Known Vulnerabilities (69 total, page 1 of 3)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-5695 Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised. -- Sep 23, 2026 HIGH CVE-2026-72819 Grav CMS vulnerable to remote code execution via .zip file upload 8.8 Sep 17, 2026 HIGH CVE-2026-69088 Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure 8.1 Sep 17, 2026 LOW GHSA-rf68-8gjr-36q7 Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty -- Sep 15, 2026 LOW CVE-2026-84307 Filament: MFA prompt leaks valid password pre-authz check 3.7 Sep 1, 2026 HIGH CVE-2026-71415 Kirby CMS: auth bypass enables chunk-upload DoS -- Aug 31, 2026 CRITICAL CVE-2026-55220 Pimcore: PHP deserialization flaw enables RCE -- Aug 28, 2026 CRITICAL CVE-2026-55634 Pimcore: DataObject field-name injection → RCE 9.9 Aug 28, 2026 HIGH GHSA-7w8c-qgxg-m7jx LibreNMS: stored XSS via unescaped SNMP/syslog data 7.1 Aug 26, 2026 CRITICAL CVE-2026-55445 Qinglong panel: unauth admin credential reset bypass -- Aug 20, 2026 HIGH GHSA-c7hr-448w-65px MeshCentral: stored XSS via unsanitized agent osdesc field 8.3 Aug 18, 2026 CRITICAL CVE-2026-62988 Froxlor: API leaks password hashes & TOTP seeds 9.0 Aug 18, 2026 HIGH CVE-2026-54347 Froxlor: stored XSS in DNS TXT record hijacks admin 8.7 Aug 18, 2026 HIGH CVE-2026-55839 Kestra: stored XSS via crafted [[link]] flow description 8.7 Aug 18, 2026 HIGH CVE-2025-30033 Siemens TIA Portal/SIMATIC: DLL hijack in installer 7.8 Aug 12, 2025 MEDIUM GHSA-xxpx-f366-4xpq Craft CMS: view-only role can restructure categories -- Aug 6, 2026 MEDIUM CVE-2026-18766 core-php-admin-panel: SQL injection via filter_col param 6.3 Aug 4, 2026 CRITICAL CVE-2026-52855 Pterodactyl Wings: egg template leaks daemon secrets 9.9 Jul 31, 2026 HIGH CVE-2026-61609 Pterodactyl Panel: global rate limiter enables panel-wide login DoS 7.5 Jul 28, 2026 HIGH CVE-2026-54593 Pterodactyl Wings: JWT reuse enables file upload bypass 8.1 Jul 28, 2026 HIGH CVE-2021-47816 Thecus NAS: authenticated command injection to RCE 8.8 Jan 16, 2026 MEDIUM CVE-2026-54497 ViewComponent: stale context leaks admin UI cross-user 6.8 Jul 15, 2026 HIGH CVE-2026-45414 Decidim: JWT replay bypasses multi-tenant isolation 8.5 Jul 13, 2026 HIGH CVE-2026-54070 SiYuan: XSS in Bazaar README steals admin API token 7.1 Jul 10, 2026 MEDIUM CVE-2026-9557 Mautic Focus: SSRF enables internal network recon 6.4 Jul 2, 2026

Showing 1–25 of 69

Frequently asked questions

What is Panel?

Panel is an AI/ML ml ui tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Panel have?

Panel has 76 known CVEs, 20 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Panel distributed in?

Panel is distributed via the pip ecosystem and categorized as ml ui.

Where does the Panel vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Panel?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Panel in your stack

Get instant alerts when new vulnerabilities affect Panel. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring