Report: Complete Guide to CVE-2026-41472 - CyberPanel < 2.4.4 Stored XSS via AI Scanner Dashboard

Report: Complete Guide to CVE-2026-41472 - CyberPanel < 2.4.4 Stored XSS via AI Scanner Dashboard

CVE ID :CVE-2026-41472 Published : April 24, 2026, 9:16 p.m. | 40 minutes ago Description :CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 24, 2026
Impact: remote code execution