Cpanel
by CPanel
CVEs (426)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20950 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). | ||
| CVE-2018-20949 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). | ||
| CVE-2018-20948 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). | ||
| CVE-2018-20929 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392). | ||
| CVE-2018-20928 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). | ||
| CVE-2018-20923 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | ||
| CVE-2018-20922 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | ||
| CVE-2018-20921 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | ||
| CVE-2018-20920 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | ||
| CVE-2018-20919 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | ||
| CVE-2018-20918 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | ||
| CVE-2018-20910 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | ||
| CVE-2018-20903 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421). | ||
| CVE-2018-20901 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). | ||
| CVE-2018-20900 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). | ||
| CVE-2018-20899 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | ||
| CVE-2019-14406 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | ||
| CVE-2018-20868 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | ||
| CVE-2018-20866 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | ||
| CVE-2018-20865 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). |
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
- risk 0.40cvss 6.1epss 0.01
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
Page 11 of 22