Known vulnerabilities in KubePi
Vendor:
1Panel-dev
Software:
KubePi
Software CPE:
cpe:2.3:a:1panel-dev:kubepi:*:*:*:*:*:*:*:*
Website:
https://1panel.cn/
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140981 - Missing Authentication for Critical Function CVE-2026-65956 |
CWE-306 | High | 2.0.0 | 05.08.2026 |
SB2026080545 |
||
| #VU140980 - Authorization Bypass Through User-Controlled Key CVE-2026-69129 |
CWE-639 | Low | 2.0.1 | 05.08.2026 |
SB2026080544 |
||
| #VU140976 - Improper Authentication CVE-2024-36111 |
CWE-287 | Low | 1.8.0 | 25.07.2024 |
SB2024072539 |
||
| #VU78646 - Exposure of sensitive information to an unauthorized actor CVE-2023-37916 |
CWE-200 | Medium | 1.6.5 | 25.07.2023 |
SB2023072542 |
||
| #VU78645 - Permissions, Privileges, and Access Controls CVE-2023-37917 |
CWE-264 | Medium | 1.6.5 | 25.07.2023 |
SB2023072542 |
||
| #VU140977 - Session Fixation CVE-2023-22479 |
CWE-384 | Medium | 1.6.4 | 09.01.2023 |
SB2023010938 |
||
| #VU140978 - Improper Access Control CVE-2023-22478 |
CWE-284 | Medium | 1.6.4 | 09.01.2023 |
SB2023010938 |
||
| #VU140979 - Use of Hard-coded Cryptographic Key CVE-2023-22463 |
CWE-321 | High | 1.6.3 | 04.01.2023 |
SB2023010457 |