Vulnerabilities
Vulnerable Software
Ajenti:  >> Ajenti  >> 1.2.13  Security Vulnerabilities
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.
CVSS Score
7.2
EPSS Score
0.001
Published
2026-04-06
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.
CVSS Score
8.1
EPSS Score
0.001
Published
2026-02-26
Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-06-18
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
CVSS Score
3.5
EPSS Score
0.002
Published
2014-04-30


Contact Us

Shodan ® - All rights reserved