Security: Ctrlpanel-gg/panel
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated RCE via Installer Accessible After Installation and Unsanitized Shell ArgumentsGHSA-jmhr-q9q5-fqwh published
May 8, 2026 by MrWeezCritical -
Missing Authorization on Admin Write Endpoints Allows RBAC BypassGHSA-pxmw-gj52-9p68 published
May 8, 2026 by MrWeezHigh -
Stored XSS in Admin Role Management via Unescaped DataTable HTML OutputGHSA-wpqj-xwhq-2mmh published
May 8, 2026 by MrWeezModerate -
Unsafe Dynamic Class Instantiation in Admin Settings Allows Potential Remote Code ExecutionGHSA-vcg3-fjrx-rg5q published
May 8, 2026 by MrWeezModerate -
Stored XSS in Ticket Reply Notifications Allows Session HijackingGHSA-cmrr-q3hw-3vqh published
May 8, 2026 by MrWeezHigh -
Missing Authorization on Admin Datatable Endpoints Allows Unauthorized Access to Sensitive DataGHSA-mj5g-j7fq-7hc4 published
May 8, 2026 by MrWeezModerate -
Stored XSS vulnerability in TicketsController priority fieldGHSA-2q43-grv2-jxwh published
Feb 11, 2025 by 1day2dieHigh