PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Exposed Panels·Updated Sep 2, 2025

CyberPanel - Command Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-51568
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
cyber_panelby cyber_panel
AFFECTED< 2.3.5SAFE ✓≥ 2.3.5
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CyberPanel - Command Injection CVE-2024-51568 Scanner | S4E