Plesk
by Plesk
CVEs (17)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68488 | Cri | 0.64 | 9.9 | 0.00 | Sep 10, 2026 | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover. | ||
| CVE-2026-68487 | Cri | 0.64 | 9.9 | 0.00 | Sep 10, 2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | ||
| CVE-2026-65646 | Cri | 0.64 | 9.9 | 0.00 | Aug 26, 2026 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. | ||
| CVE-2026-64637 | Cri | 0.64 | 9.9 | 0.00 | Aug 7, 2026 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. | ||
| CVE-2026-58046 | Cri | 0.64 | 9.9 | 0.00 | Jul 30, 2026 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. | ||
| CVE-2026-44962 | Cri | 0.64 | 9.9 | 0.01 | May 29, 2026 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system… | ||
| CVE-2026-64639 | Cri | 0.60 | — | 0.00 | Aug 12, 2026 | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator. | ||
| CVE-2025-66430 | Cri | 0.59 | 9.1 | 0.00 | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. | ||
| CVE-2026-65647 | Hig | 0.57 | — | 0.01 | Aug 26, 2026 | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | ||
| CVE-2023-0829 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription. | ||
| CVE-2021-45008 | Hig | 0.57 | 8.8 | 0.02 | Feb 21, 2022 | Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users | ||
| CVE-2026-65642 | Hig | 0.56 | — | 0.00 | Aug 26, 2026 | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. | ||
| CVE-2026-67397 | Hig | 0.55 | — | 0.00 | Sep 4, 2026 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | ||
| CVE-2022-45130 | Med | 0.42 | 6.5 | 0.00 | Nov 10, 2022 | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are… | ||
| CVE-2021-45007 | Med | 0.42 | 6.5 | 0.01 | Feb 20, 2022 | Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users | ||
| CVE-2023-4931 | Med | 0.41 | 6.3 | 0.00 | Nov 27, 2023 | Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll,… | ||
| CVE-2026-56843 | Cri | 0.00 | 9.9 | 0.01 | Jul 8, 2026 | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol… |
- risk 0.64cvss 9.9epss 0.00
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
- risk 0.64cvss 9.9epss 0.00
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
- risk 0.64cvss 9.9epss 0.00
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
- risk 0.64cvss 9.9epss 0.00
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
- risk 0.64cvss 9.9epss 0.00
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
- risk 0.64cvss 9.9epss 0.01
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system…
- risk 0.60cvss —epss 0.00
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
- risk 0.59cvss 9.1epss 0.00
Plesk 18.0 has Incorrect Access Control.
- risk 0.57cvss —epss 0.01
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
- risk 0.57cvss 8.8epss 0.01
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
- risk 0.57cvss 8.8epss 0.02
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
- risk 0.56cvss —epss 0.00
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
- risk 0.55cvss —epss 0.00
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
- risk 0.42cvss 6.5epss 0.00
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are…
- risk 0.42cvss 6.5epss 0.01
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
- risk 0.41cvss 6.3epss 0.00
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll,…
- risk 0.00cvss 9.9epss 0.01
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol…