Cockpit Content Platform
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-23695 cockpit-hq/cockpit is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.14.0. | 0.0.0 - 2.14.0 | Medium |
CVE-2026-38993 cockpit-hq/cockpit is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.14.0. | 0.0.0 - 2.14.0 | Medium |
CVE-2026-38991 cockpit-hq/cockpit is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 2.14.0. | 0.0.0 - 2.14.0 | High |
CVE-2026-38992 cockpit-hq/cockpit is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 2.14.0. | 0.0.0 - 2.14.0 | Critical |
CVE-2026-6626 cockpit-hq/cockpit is vulnerable to Improper Input Validation in versions 0.0.0 - 2.14.0. | 0.0.0 - 2.14.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^2.0.0 | — | — |
symfony/console Version ^5.3 | — | — |
symfony/process Version ^6.2 | — | — |
colinodell/json5 Version ^2.2 | — | — |
firebase/php-jwt Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant