VDB
Sign up

package

Packagist/pterodactyl/panel

pkg:packagist/pterodactyl/panel

MEDIUMPackagist
GHSA-5822-pw57-vv37

XSS vulnerability when listing users on add & modify server pages.

Modified: 12/2/2024

HIGH8.1Packagist
GHSA-5vfx-8w6m-h3v4· CVE-2021-41129

Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification

Modified: 7/8/2026

MEDIUM6.0Packagist
GHSA-7v3x-h7r2-34jv

Insufficient Session Expiration in Pterodactyl API

Modified: 12/4/2024

MEDIUMPackagist
GHSA-j7f5-gfqm-pcx3

Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system

Modified: 9/10/2026

LOWPackagist
GHSA-mgr9-6c2j-jxrq

Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”

Modified: 12/30/2025

HIGH7.5Packagist
GHSA-xvc3-826v-xf47· CVE-2026-61609

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

Modified: 7/28/2026