Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26114 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573). | ||
| CVE-2020-26113 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). | ||
| CVE-2020-26111 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). | ||
| CVE-2020-26110 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564). | ||
| CVE-2020-10114 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). | ||
| CVE-2020-10113 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). | ||
| CVE-2019-20493 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). | ||
| CVE-2019-17380 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | ||
| CVE-2019-17379 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). | ||
| CVE-2019-17378 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). | ||
| CVE-2019-17377 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). | ||
| CVE-2019-17376 | Med | 0.40 | 6.1 | 0.00 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). | ||
| CVE-2016-10795 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). | ||
| CVE-2017-18472 | Med | 0.40 | 6.1 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198). | ||
| CVE-2016-10769 | Med | 0.40 | 6.1 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162). | ||
| CVE-2017-18456 | Med | 0.40 | 6.1 | 0.01 | Aug 2, 2019 | cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217). | ||
| CVE-2018-20953 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | ||
| CVE-2018-20951 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). | ||
| CVE-2018-20950 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). | ||
| CVE-2018-20949 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). |
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
- risk 0.40cvss 6.1epss 0.01
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
- risk 0.40cvss 6.1epss 0.01
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
- risk 0.40cvss 6.1epss 0.01
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
- risk 0.40cvss 6.1epss 0.00
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
- risk 0.40cvss 6.1epss 0.01
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
- risk 0.40cvss 6.1epss 0.01
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
- risk 0.40cvss 6.1epss 0.01
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- risk 0.40cvss 6.1epss 0.01
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
Page 10 of 22