Skip to main content

Vendor/product archive

pterodactyl / panel CVEs

Beta · best-effort

9 CVEs tagged to pterodactyl / panel1 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-26016

Published Feb 19, 2026

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-69198

Published Jan 19, 2026

Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69197

Published Jan 6, 2026

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68954

Published Jan 6, 2026

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34067

Published May 3, 2024

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross si…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41273

Published Nov 17, 2021

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could exe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41176

Published Oct 25, 2021

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a sig…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41129

Published Oct 6, 2021

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1