VYPR

Plesk

by Plesk

CVEs (17)

  • CVE-2026-68488CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

  • CVE-2026-68487CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

  • CVE-2026-65646CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

  • CVE-2026-64637CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

  • CVE-2026-58046CriJul 30, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

  • CVE-2026-44962CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system…

  • CVE-2026-64639CriAug 12, 2026
    risk 0.60cvss epss 0.00

    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

  • CVE-2025-66430CriDec 12, 2025
    risk 0.59cvss 9.1epss 0.00

    Plesk 18.0 has Incorrect Access Control.

  • CVE-2026-65647HigAug 26, 2026
    risk 0.57cvss epss 0.01

    Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

  • CVE-2023-0829HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

  • CVE-2021-45008HigFeb 21, 2022
    risk 0.57cvss 8.8epss 0.02

    Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

  • CVE-2026-65642HigAug 26, 2026
    risk 0.56cvss epss 0.00

    Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

  • CVE-2026-67397HigSep 4, 2026
    risk 0.55cvss epss 0.00

    Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

  • CVE-2022-45130MedNov 10, 2022
    risk 0.42cvss 6.5epss 0.00

    Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are…

  • CVE-2021-45007MedFeb 20, 2022
    risk 0.42cvss 6.5epss 0.01

    Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

  • CVE-2023-4931MedNov 27, 2023
    risk 0.41cvss 6.3epss 0.00

    Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll,…

  • CVE-2026-56843CriJul 8, 2026
    risk 0.00cvss 9.9epss 0.01

    Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol…