Panel Vulnerabilities

pip ML UI

AI Threat Alert tracks 55 known vulnerabilities in Panel, 16 rated critical — an AI/ML ml ui in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
26
Risk Score
55
Total CVEs
16
Critical
pip
Ecosystem
Aug 6, 2026
Last CVE
61%
Patch Rate
16d
Avg Time to Patch
5,731 stars 620 forks 1,112 issues 499 dependents Last push Aug 14, 2026
View on GitHub
OpenSSF Scorecard 6.8/10

Known Vulnerabilities (53 total, page 2 of 3)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2025-14014 Smart Panel: unauthenticated file upload enables RCE 9.8 Feb 12, 2026 CRITICAL CVE-2024-6684 Nova Panel N7: auth bypass via alternate channel (EOL) -- Aug 12, 2024 CRITICAL CVE-2024-5958 Panel: SQL injection enables OS command execution -- Sep 18, 2024 CRITICAL CVE-2024-5960 Panel: plaintext credential storage enables domain compromise 9.8 Sep 18, 2024 CRITICAL CVE-2024-5959 Panel: Stored XSS enables session hijack in ML dashboards -- Sep 18, 2024 CRITICAL CVE-2024-6878 Panel: file exposure enables sensitive ML data collection -- Sep 18, 2024 CRITICAL CVE-2024-6877 Panel: Reflected XSS enables session hijack in ML UI -- Sep 18, 2024 MEDIUM CVE-2019-6576 SIMATIC WinCC: TLS key disclosure enables traffic decryption 6.5 May 14, 2019 CRITICAL CVE-2024-13147 B2B Login Panel: SQLi enables unauthenticated DB access 9.8 Mar 5, 2025 CRITICAL CVE-2024-13152 Mobuy Panel: SQLi allows unauthenticated DB takeover 10.0 Feb 14, 2025 CRITICAL GHSA-8whc-2wmv-ww35 AVideo YPTSocket: Stored DOM XSS enables admin takeover 9.6 Jun 4, 2026 CRITICAL CVE-2026-2586 GlassFish: authenticated RCE via admin console 9.1 May 19, 2026 HIGH CVE-2026-41234 Froxlor: DNS zone injection via unsanitized TXT record 7.6 Jun 3, 2026 HIGH GHSA-f9rx-7wf7-jr36 Froxlor: 2FA bypass via API grants full account access 8.1 Jun 3, 2026 MEDIUM CVE-2026-47745 Shopper: auth bypass enables full checkout shutdown 6.5 May 29, 2026 CRITICAL CVE-2026-47744 Shopper: RBAC bypass allows full admin takeover 9.9 May 29, 2026 MEDIUM CVE-2026-47742 Shopper: authz bypass lets any user mutate product data 6.5 May 29, 2026 HIGH CVE-2026-41235 Froxlor: shell whitelist bypass grants host shell access -- May 29, 2026 HIGH CVE-2026-41236 Froxlor: symlink-following grants customer root SSH access 8.8 May 29, 2026 MEDIUM CVE-2026-45334 Kirby CMS: auth bypass leaks admin emails via content lock -- May 27, 2026 HIGH CVE-2026-45368 Kirby CMS: Stored XSS via javascript: URI scheme bypass -- May 27, 2026 HIGH CVE-2026-44174 Kirby: unsafe reflection allows privilege escalation -- May 26, 2026 UNKNOWN CVE-2026-44175 Kirby CMS: stored XSS in list field enables session hijack -- May 26, 2026 UNKNOWN CVE-2026-44176 Kirby CMS: auth bypass exposes restricted page drafts -- May 26, 2026 MEDIUM CVE-2026-44898 mistune: XSS in TOC render via unescaped heading ID 6.1 May 14, 2026

Showing 26–50 of 53

Frequently asked questions

What is Panel?

Panel is an AI/ML ml ui tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Panel have?

Panel has 55 known CVEs, 16 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Panel distributed in?

Panel is distributed via the pip ecosystem and categorized as ml ui.

Where does the Panel vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Panel?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Panel in your stack

Get instant alerts when new vulnerabilities affect Panel. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring