xiaopi CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

xiaopi vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to xiaopi, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-5332 A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.0 0.19% 2026-04-02 2026-04-29
CVE-2026-2122 A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.1 0.27% 2026-02-08 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence