Home/Product/portainer
Product

portainer

25 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44885
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
5.5MEDIUM
CVE-2026-44884
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
6.5MEDIUM
CVE-2026-44883
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
7.5HIGH
CVE-2026-44882
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
8.1HIGH
CVE-2026-44881
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
9.9CRITICAL
CVE-2026-44850
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
8.5HIGH
CVE-2026-44849
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
8.8HIGH
CVE-2026-44848
>= 2.33.0 and < 2.33.8
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage D
8.8HIGH
CVE-2024-33662
< 2.20.2
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
7.5HIGH
CVE-2024-33661
< 2.20.0
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
9.1CRITICAL
CVE-2024-29296
all versions
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a d
5.3MEDIUM
CVE-2022-24961
< 2.11.1
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past
9.8CRITICAL
CVE-2021-42650
< 2.9.1
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
6.1MEDIUM
CVE-2020-24264
<= 1.24.1
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restric
9.8CRITICAL
CVE-2020-24263
<= 1.24.1
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution
8.8HIGH
CVE-2019-16878
< 1.22.1
Portainer before 1.22.1 has XSS (issue 2 of 2).
5.4MEDIUM
CVE-2019-16877
< 1.22.1
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
8.8HIGH
CVE-2019-16876
< 1.22.1
Portainer before 1.22.1 allows Directory Traversal.
7.5HIGH
CVE-2019-16872
< 1.22.1
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
9.9CRITICAL
CVE-2019-16874
< 1.22.1
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
6.5MEDIUM
CVE-2019-16873
< 1.22.1
Portainer before 1.22.1 has XSS (issue 1 of 2).
5.4MEDIUM
CVE-2018-19466
< 1.20.0
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cl
9.8CRITICAL
CVE-2018-19367
<= 1.19.2
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This
9.8CRITICAL
CVE-2018-16316
<= 1.19.1
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrar
5.4MEDIUM
CVE-2018-12678
< 1.18.0
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the
9.8CRITICAL
threatengine.sh