portainer records
26 published records for vendor portainer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 38.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-522 Insufficiently Protected Credentials1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-24264No exploit | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.portainer · portainer · CWE-863 | Critical9.8 | — | 4.1% | Mar 16, 2021 |
40Plan | CVE-2018-19466Proof of concept | A vulnerability was found in Portainer before 1.20.0.portainer · portainer · CWE-522 | Critical9.8 | — | 3.7% | Mar 27, 2019 |
40Plan | CVE-2018-12678No exploit | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websockeportainer · portainer · CWE-918 | Critical9.8 | — | 2.3% | Jun 22, 2018 |
39Monitor | CVE-2022-24961No exploit | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.portainer · portainer | Critical9.8 | — | 1.6% | Feb 11, 2022 |
39Monitor | CVE-2018-19367No exploit | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.portainer · portainer | Critical9.8 | — | 1.5% | Nov 20, 2018 |
39Monitor | CVE-2019-16872No exploit | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).portainer · portainer | Critical9.9 | — | 1.4% | Nov 7, 2019 |
37Monitor | CVE-2026-44849No exploit | Portainer: Endpoint security bypass via Swarm service create/updateportainer · portainer · CWE-862 | Critical9.4 | — | 0.4% | May 28, 2026 |
37Monitor | CVE-2026-44848Proof of concept | Portainer: Missing authorization on Docker plugin endpoints allows host RCEportainer · portainer · CWE-862 | Critical9.4 | — | 0.4% | May 28, 2026 |
36Monitor | CVE-2024-33661No exploit | Portainer before 2.20.0 allows redirects when the target is not index.yaml.portainer · portainer · CWE-601 | Critical9.1 | — | 0.6% | Apr 25, 2024 |
35Monitor | CVE-2020-24263No exploit | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.portainer · portainer · CWE-732 | High8.8 | — | 1.6% | Mar 16, 2021 |
35Monitor | CVE-2019-16877No exploit | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).portainer · portainer | High8.8 | — | 1.0% | Nov 7, 2019 |
34Monitor | CVE-2026-44881Proof of concept | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer · portainer · CWE-59 | High8.5 | — | 0.6% | May 28, 2026 |
34Monitor | CVE-2026-44850No exploit | Portainer: Bind-mount restriction bypass via HostConfig.Mountsportainer · portainer · CWE-863 | High8.5 | — | 0.3% | May 28, 2026 |
32Monitor | CVE-2026-44882No exploit | Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorizationportainer · portainer · CWE-863 | High8.1 | — | 0.5% | May 28, 2026 |
30Monitor | CVE-2019-16876No exploit | Portainer before 1.22.1 allows Directory Traversal.portainer · portainer · CWE-22 | High7.5 | — | 1.4% | Nov 7, 2019 |
30Monitor | CVE-2026-44883No exploit | Portainer: JWT accepted in URL query leaks tokens to logs and referersportainer · portainer · CWE-598 | High7.7 | — | 0.5% | May 28, 2026 |
30Monitor | CVE-2024-33662No exploit | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.portainer · portainer · CWE-326 | High7.5 | — | 0.3% | Oct 2, 2024 |
28Monitor | CVE-2026-55761No exploit | Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instancesportainer · portainer · CWE-287 | High7.1 | — | 0.5% | Jul 8, 2026 |
26Monitor | CVE-2019-16874No exploit | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).portainer · portainer | Medium6.5 | — | 0.9% | Nov 7, 2019 |
24Monitor | CVE-2021-42650No exploit | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.portainer · portainer · CWE-79 | Medium6.1 | — | 0.6% | Oct 18, 2021 |
24Monitor | CVE-2026-44884No exploit | Portainer: Missing authorization on custom template file endpoint exposes template contentportainer · portainer · CWE-862 | Medium6.0 | — | 0.4% | May 28, 2026 |
22Monitor | CVE-2026-44885No exploit | Portainer: Path traversal in backup archive extraction allows arbitrary file writeportainer · portainer · CWE-22 | Medium5.5 | — | 0.8% | May 28, 2026 |
21Monitor | CVE-2024-29296Proof of concept | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Medium5.3 | — | 1.3% | Apr 10, 2024 |
21Monitor | CVE-2018-16316No exploit | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScriportainer · portainer · CWE-79 | Medium5.4 | — | 0.8% | Sep 1, 2018 |
21Monitor | CVE-2019-16873No exploit | Portainer before 1.22.1 has XSS (issue 1 of 2).portainer · portainer · CWE-79 | Medium5.4 | — | 0.5% | Nov 7, 2019 |
- CVE-2020-2426440Plan
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.
CriticalCVSS 9.8No exploitEPSS 4%portainer · portainerMar 16, 2021
- CVE-2018-1946640Plan
A vulnerability was found in Portainer before 1.20.0.
CriticalCVSS 9.8Proof of conceptEPSS 4%portainer · portainerMar 27, 2019
- CVE-2018-1267840Plan
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke
CriticalCVSS 9.8No exploitEPSS 2%portainer · portainerJun 22, 2018
- CVE-2022-2496139Monitor
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
CriticalCVSS 9.8No exploitEPSS 2%portainer · portainerFeb 11, 2022
- CVE-2018-1936739Monitor
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.
CriticalCVSS 9.8No exploitEPSS 1%portainer · portainerNov 20, 2018
- CVE-2019-1687239Monitor
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
CriticalCVSS 9.9No exploitEPSS 1%portainer · portainerNov 7, 2019
- CVE-2026-4484937Monitor
Portainer: Endpoint security bypass via Swarm service create/update
CriticalCVSS 9.4No exploitEPSS 0%portainer · portainerMay 28, 2026
- CVE-2026-4484837Monitor
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
CriticalCVSS 9.4Proof of conceptEPSS 0%portainer · portainerMay 28, 2026
- CVE-2024-3366136Monitor
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CriticalCVSS 9.1No exploitEPSS 1%portainer · portainerApr 25, 2024
- CVE-2020-2426335Monitor
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.
HighCVSS 8.8No exploitEPSS 2%portainer · portainerMar 16, 2021
- CVE-2019-1687735Monitor
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
HighCVSS 8.8No exploitEPSS 1%portainer · portainerNov 7, 2019
- CVE-2026-4488134Monitor
Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
HighCVSS 8.5Proof of conceptEPSS 1%portainer · portainerMay 28, 2026
- CVE-2026-4485034Monitor
Portainer: Bind-mount restriction bypass via HostConfig.Mounts
HighCVSS 8.5No exploitEPSS 0%portainer · portainerMay 28, 2026
- CVE-2026-4488232Monitor
Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
HighCVSS 8.1No exploitEPSS 0%portainer · portainerMay 28, 2026
- CVE-2019-1687630Monitor
Portainer before 1.22.1 allows Directory Traversal.
HighCVSS 7.5No exploitEPSS 1%portainer · portainerNov 7, 2019
- CVE-2026-4488330Monitor
Portainer: JWT accepted in URL query leaks tokens to logs and referers
HighCVSS 7.7No exploitEPSS 0%portainer · portainerMay 28, 2026
- CVE-2024-3366230Monitor
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
HighCVSS 7.5No exploitEPSS 0%portainer · portainerOct 2, 2024
- CVE-2026-5576128Monitor
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
HighCVSS 7.1No exploitEPSS 0%portainer · portainerJul 8, 2026
- CVE-2019-1687426Monitor
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
MediumCVSS 6.5No exploitEPSS 1%portainer · portainerNov 7, 2019
- CVE-2021-4265024Monitor
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
MediumCVSS 6.1No exploitEPSS 1%portainer · portainerOct 18, 2021
- CVE-2026-4488424Monitor
Portainer: Missing authorization on custom template file endpoint exposes template content
MediumCVSS 6.0No exploitEPSS 0%portainer · portainerMay 28, 2026
- CVE-2026-4488522Monitor
Portainer: Path traversal in backup archive extraction allows arbitrary file write
MediumCVSS 5.5No exploitEPSS 1%portainer · portainerMay 28, 2026
- CVE-2024-2929621Monitor
A user enumeration vulnerability was found in Portainer CE 2.19.4.
MediumCVSS 5.3Proof of conceptEPSS 1%portainer · portainerApr 10, 2024
- CVE-2018-1631621Monitor
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri
MediumCVSS 5.4No exploitEPSS 1%portainer · portainerSep 1, 2018
- CVE-2019-1687321Monitor
Portainer before 1.22.1 has XSS (issue 1 of 2).
MediumCVSS 5.4No exploitEPSS 1%portainer · portainerNov 7, 2019