Cpanel
by CPanel
CVEs (427)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10780 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180). | ||
| CVE-2016-10779 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179). | ||
| CVE-2016-10778 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178). | ||
| CVE-2016-10777 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177). | ||
| CVE-2016-10776 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174). | ||
| CVE-2017-18481 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211). | ||
| CVE-2017-18473 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199). | ||
| CVE-2017-18471 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197). | ||
| CVE-2016-10774 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172). | ||
| CVE-2016-10767 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159). | ||
| CVE-2017-18454 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262). | ||
| CVE-2017-18451 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257). | ||
| CVE-2017-18448 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252). | ||
| CVE-2017-18444 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248). | ||
| CVE-2017-18442 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246). | ||
| CVE-2017-18420 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). | ||
| CVE-2017-18419 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). | ||
| CVE-2017-18418 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). | ||
| CVE-2017-18417 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). | ||
| CVE-2017-18408 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). |
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
- risk 0.35cvss 5.4epss 0.01
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
Page 14 of 22