CVE Feed

    Dashboard / CVE / CVE-2026-41472

    CVE-2026-41472

    CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.

    Published:Apr 24, 2026
    Last Modified:Aug 11, 2026
    EPS:Apr 24, 2026
    EPSS Score:0.00504
    CVSS Score:6.1

    Affected Products

    Vendor
    Cyberpanel
    Product
    Cyberpanel
    Vendor
    Usmannasir
    Product
    Cyberpanel

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High