Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Modified: 6/20/2025
package
pkg:packagist/pterodactyl/panel
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Modified: 6/20/2025
Pterodactyl panel's admin area vulnerable to Cross-site Scripting
Modified: 9/10/2026
XSS vulnerability when listing users on add & modify server pages.
Modified: 12/2/2024
Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification
Modified: 7/8/2026
Insufficient Session Expiration in Pterodactyl API
Modified: 12/4/2024
Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled
Modified: 10/25/2024
Pterodactyl vulnerable to 2FA Sniffing
Modified: 9/10/2026
Pterodactyl has a database resource limit bypass via race condition in Client API
Modified: 9/10/2026
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Modified: 2/19/2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Modified: 9/10/2026
Pterodactyl improperly locks resources allowing raced queries to create more resources than alloted
Modified: 2/3/2026
pterodactyl/panel CSRF allowing an external page to trigger a user logout event
Modified: 7/8/2026
Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”
Modified: 12/30/2025
Pterodactyl TOTPs can be reused during validity window
Modified: 2/3/2026
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
Modified: 7/8/2026
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Modified: 7/28/2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Modified: 2/3/2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Modified: 8/18/2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
Modified: 2/23/2026