Cpanel
by CPanel
CVEs (427)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20908 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). | ||
| CVE-2018-20902 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | ||
| CVE-2018-20891 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436). | ||
| CVE-2018-20888 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). | ||
| CVE-2019-14409 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | ||
| CVE-2019-14404 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). | ||
| CVE-2019-14394 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489). | ||
| CVE-2018-20870 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | ||
| CVE-2004-1603 | Med | 0.36 | 5.5 | 0.02 | Oct 18, 2004 | cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled. | ||
| CVE-2020-12784 | Med | 0.35 | 5.3 | 0.01 | May 11, 2020 | cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505). | ||
| CVE-2020-10116 | Med | 0.35 | 5.3 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541). | ||
| CVE-2019-20497 | Med | 0.35 | 5.4 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). | ||
| CVE-2019-20491 | Med | 0.35 | 5.4 | 0.01 | Mar 16, 2020 | cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508). | ||
| CVE-2012-6449 | Med | 0.35 | 5.4 | 0.01 | Feb 10, 2020 | The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | ||
| CVE-2016-10806 | Med | 0.35 | 5.4 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110). | ||
| CVE-2016-10791 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2019 | cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559). | ||
| CVE-2016-10784 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184). | ||
| CVE-2016-10783 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182). | ||
| CVE-2016-10782 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181). | ||
| CVE-2016-10781 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180). |
- risk 0.36cvss 5.5epss 0.00
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
- risk 0.36cvss 5.5epss 0.00
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
- risk 0.36cvss 5.5epss 0.00
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
- risk 0.36cvss 5.5epss 0.00
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
- risk 0.36cvss 5.5epss 0.00
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
- risk 0.36cvss 5.5epss 0.00
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
- risk 0.36cvss 5.5epss 0.00
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
- risk 0.36cvss 5.5epss 0.00
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
- risk 0.36cvss 5.5epss 0.02
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
- risk 0.35cvss 5.3epss 0.01
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
- risk 0.35cvss 5.3epss 0.01
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
- risk 0.35cvss 5.4epss 0.01
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
- risk 0.35cvss 5.4epss 0.01
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
- risk 0.35cvss 5.3epss 0.01
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
Page 13 of 22