Cpanel
by CPanel
CVEs (426)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10813 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118). | ||
| CVE-2016-10827 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96). | ||
| CVE-2016-10822 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88). | ||
| CVE-2018-20935 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). | ||
| CVE-2018-20933 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). | ||
| CVE-2016-10841 | Med | 0.35 | 5.3 | 0.01 | Aug 1, 2019 | The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). | ||
| CVE-2018-20916 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | ||
| CVE-2018-20915 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | ||
| CVE-2018-20905 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). | ||
| CVE-2016-10854 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). | ||
| CVE-2016-10853 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). | ||
| CVE-2016-10851 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). | ||
| CVE-2018-20885 | Med | 0.35 | 5.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | ||
| CVE-2018-20884 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | ||
| CVE-2018-20881 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | ||
| CVE-2018-20878 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | ||
| CVE-2018-20877 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | ||
| CVE-2018-20876 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | ||
| CVE-2018-20875 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | ||
| CVE-2018-20874 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). |
- risk 0.35cvss 5.4epss 0.01
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
- risk 0.35cvss 5.4epss 0.01
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
- risk 0.35cvss 5.4epss 0.01
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
- risk 0.35cvss 5.3epss 0.01
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
- risk 0.35cvss 5.4epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
- risk 0.35cvss 5.3epss 0.01
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
Page 15 of 22