Total
9 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-26016 | 1 Pterodactyl | 1 Panel | 2026-02-20 | N/A | 8.1 HIGH |
|
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, even if that server is associated with a different node. This issue stems from missing logic to verify that the node requesting server data is the same node that the server is associated with. Any authent ...
Show More |
|||||
| CVE-2025-69198 | 1 Pterodactyl | 1 Panel | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle. However, in versions prior to 1.12.0, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than ...
Show More |
|||||
| CVE-2025-68954 | 1 Pterodactyl | 2 Panel, Wings | 2026-01-12 | N/A | 5.4 MEDIUM |
|
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability ...
Show More |
|||||
| CVE-2025-69197 | 1 Pterodactyl | 1 Panel | 2026-01-12 | N/A | 6.5 MEDIUM |
|
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in the system. This allows an attacker who intercepts that token to use it in addition to a known username/password during the 60-second token validity window. The attacker must have intercepted a valid 2FA token (for exam ...
Show More |
|||||
| CVE-2024-34067 | 1 Pterodactyl | 1 Panel | 2025-06-06 | N/A | 6.1 MEDIUM |
|
Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. Specifically, the following things are impacted: Egg Docker images and Egg variables: Name, Environment variable, Default value, Description, Validation rules. Additionally, certain fields would reflect malicious input, b ...
Show More |
|||||
| CVE-2021-41273 | 1 Pterodactyl | 1 Panel | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point would any data be exposed to the malicious user, this would simply trigger email spam to an administrative user, or generate a single auto-deployment token unexpectedly. This token is n ...
Show More |
|||||
| CVE-2021-41176 | 1 Pterodactyl | 1 Panel | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a specific Panel instance, and serves only to sign a user out. **No user details are leaked, nor is any user data affected, this is simply an annoyance at worst.** This is fixed in versio ...
Show More |
|||||
| CVE-2021-41129 | 1 Pterodactyl | 1 Panel | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious actor to authenticate as a random user in the Panel. The malicious user must target an account with two-factor authentication enabled, and then must provide a correct two-factor authe ...
Show More |
|||||
| CVE-2019-1020002 | 1 Pterodactyl | 1 Panel | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
|
|||||