CVE-2024-56112: CyberPanel

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

Affected products

  • CyberPanel CyberPanel: before 2024-11-11 (fixed in 2024-11-11)

Published 2024-12-16. Last modified 2026-06-17.