Agentejo
Agentejo Cockpit: vulnerabilidades y CVE
Agentejo Cockpit tiene 32 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses2
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13533 | Media (5.5) | 0.48% | — | 29 jun 2026 | A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation… |
| CVE-2026-31891 | Media (6.5) | 0.39% | — | 18 mar 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation… |
| CVE-2025-7053 | Media (5.1) | 0.33% | — | 4 jul 2025 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross… |
| CVE-2024-4825 | Crítica (9.8) | 0.72% | — | 14 may 2024 | A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the… |
| CVE-2024-2001 | Media (5.4) | 0.32% | — | 29 feb 2024 | A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed… |
| CVE-2023-41564 | Media (6.1) | 0.98% | — | 8 sept 2023 | An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file. |
| CVE-2023-4451 | Media (6.1) | 2.5% | — | 20 ago 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4433 | Media (5.4) | 0.56% | — | 19 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4432 | Media (6.1) | 0.61% | — | 19 ago 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4422 | Media (4.8) | 0.64% | — | 18 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
| CVE-2023-4395 | Media (5.4) | 0.57% | — | 17 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4321 | Media (6.1) | 0.64% | — | 14 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. |
| CVE-2023-4196 | Media (5.4) | 0.47% | — | 6 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
| CVE-2023-4195 | Alta (8.8) | 1.1% | — | 6 ago 2023 | PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
| CVE-2023-37650 | Alta (8.8) | 0.53% | — | 20 jul 2023 | A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. |
| CVE-2023-37649 | Alta (7.5) | 0.88% | — | 20 jul 2023 | Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data. |
| CVE-2023-1313 | Alta (8.8) | 0.99% | — | 10 mar 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. |
| CVE-2023-1160 | Media (5.5) | 0.35% | — | 3 mar 2023 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. |
| CVE-2021-32857 | Media (6.1) | 0.71% | — | 21 feb 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS)… |
| CVE-2023-0780 | Media (5.4) | 0.37% | — | 11 feb 2023 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. |
| CVE-2023-0759 | Alta (8.8) | 0.34% | — | 9 feb 2023 | Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. |
| CVE-2022-2818 | Alta (8.8) | 1.7% | — | 15 ago 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2. |
| CVE-2022-2713 | Crítica (9.8) | 1.3% | — | 8 ago 2022 | Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. |
| CVE-2020-35131 | Crítica (9.8) | 51% | — | 8 ene 2021 | Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the… |
| CVE-2020-35848 | Crítica (9.8) | 75% | — | 30 dic 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. |
| CVE-2020-35847 | Crítica (9.8) | 98% | — | 30 dic 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. |
| CVE-2020-35846 | Crítica (9.8) | 93% | — | 30 dic 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. |
| CVE-2020-14408 | Media (6.1) | 3.0% | — | 17 jun 2020 | An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a… |
| CVE-2018-15540 | Crítica (9.8) | 2.3% | — | 15 oct 2018 | Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory… |
| CVE-2018-15539 | Alta (8.8) | 0.58% | — | 15 oct 2018 | Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. |