VYPR

Plesk

by WebPros

CVEs (2)

  • CVE-2025-66431HigDec 3, 2025
    risk 0.51cvss 7.8epss 0.00

    WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."

  • CVE-2026-56843Jul 8, 2026
    risk 0.00cvss epss 0.00

    Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol…