VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2026-41940CriKEVApr 29, 2026
    risk 0.93cvss 9.8epss 0.98

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  • CVE-2020-26108CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

  • CVE-2020-26105CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

  • CVE-2020-26101CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

  • CVE-2020-26100CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.02

    chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

  • CVE-2020-26098CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.03

    cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

  • CVE-2020-10121CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).

  • CVE-2020-10119CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

  • CVE-2019-20498CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

  • CVE-2016-10817CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

  • CVE-2016-10824CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

  • CVE-2016-10858CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

  • CVE-2016-10855CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

  • CVE-2018-20887CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.01

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

  • CVE-2018-20863CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

  • CVE-2026-58048CriJul 31, 2026
    risk 0.61cvss epss 0.01

    Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

  • CVE-2006-5014HigSep 27, 2006
    risk 0.61cvss 8.8epss 0.04

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.

  • CVE-2020-10118CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).

  • CVE-2020-10117CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).

  • CVE-2025-66429HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

Page 1 of 22