Cpanel
by CPanel
CVEs (426)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20867 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | ||
| CVE-2019-14387 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). | ||
| CVE-2018-16236 | Med | 0.40 | 6.1 | 0.01 | Aug 30, 2018 | cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering. | ||
| CVE-2017-5614 | Med | 0.40 | 6.1 | 0.01 | Mar 3, 2017 | Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter. | ||
| CVE-2017-18443 | Med | 0.38 | 5.8 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247). | ||
| CVE-2018-20945 | Med | 0.37 | 5.7 | 0.01 | Aug 1, 2019 | bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). | ||
| CVE-2026-58047 | Med | 0.36 | — | 0.01 | Jul 31, 2026 | HTTP Smuggling in cPanel allows potential leak of credentials. | ||
| CVE-2021-38590 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2021 | In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584). | ||
| CVE-2019-20496 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). | ||
| CVE-2016-10799 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2019 | cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). | ||
| CVE-2017-18449 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254). | ||
| CVE-2017-18416 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). | ||
| CVE-2017-18405 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). | ||
| CVE-2017-18396 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329). | ||
| CVE-2017-18385 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). | ||
| CVE-2018-20947 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). | ||
| CVE-2018-20941 | Med | 0.36 | 5.6 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). | ||
| CVE-2018-20924 | Med | 0.36 | 5.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). | ||
| CVE-2018-20917 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | ||
| CVE-2018-20908 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). |
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
- risk 0.40cvss 6.1epss 0.01
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
- risk 0.38cvss 5.8epss 0.01
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
- risk 0.37cvss 5.7epss 0.01
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
- risk 0.36cvss —epss 0.01
HTTP Smuggling in cPanel allows potential leak of credentials.
- risk 0.36cvss 5.5epss 0.00
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
- risk 0.36cvss 5.5epss 0.00
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
- risk 0.36cvss 5.5epss 0.00
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
- risk 0.36cvss 5.5epss 0.00
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
- risk 0.36cvss 5.5epss 0.00
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
- risk 0.36cvss 5.6epss 0.00
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
- risk 0.36cvss 5.5epss 0.01
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
- risk 0.36cvss 5.5epss 0.00
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
- risk 0.36cvss 5.5epss 0.00
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
Page 12 of 22