Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14390 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). | ||
| CVE-2019-14386 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). | ||
| CVE-2017-11441 | Med | 0.35 | 5.4 | 0.01 | Jul 19, 2017 | The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297. | ||
| CVE-2018-20886 | Med | 0.34 | 5.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418). | ||
| CVE-2019-14393 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486). | ||
| CVE-2017-18441 | Med | 0.33 | 5.0 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245). | ||
| CVE-2017-18464 | Med | 0.32 | 4.9 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226). | ||
| CVE-2017-18453 | Med | 0.32 | 4.9 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260). | ||
| CVE-2018-20913 | Med | 0.32 | 4.9 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | ||
| CVE-2017-18430 | Med | 0.31 | 4.7 | 0.01 | Aug 2, 2019 | In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294). | ||
| CVE-2017-18407 | Med | 0.31 | 4.8 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). | ||
| CVE-2021-38586 | Med | 0.29 | 4.4 | 0.00 | Aug 11, 2021 | In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589). | ||
| CVE-2017-18465 | Med | 0.29 | 4.4 | 0.00 | Aug 5, 2019 | cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227). | ||
| CVE-2017-18457 | Med | 0.29 | 4.4 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218). | ||
| CVE-2017-18450 | Med | 0.29 | 4.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255). | ||
| CVE-2017-18437 | Med | 0.29 | 4.4 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240). | ||
| CVE-2018-20889 | Med | 0.29 | 4.4 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | ||
| CVE-2016-10797 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2019 | cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133). | ||
| CVE-2017-18467 | Med | 0.28 | 4.3 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229). | ||
| CVE-2017-18461 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223). |
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
- risk 0.35cvss 5.4epss 0.01
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
- risk 0.34cvss 5.3epss 0.00
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
- risk 0.34cvss 5.3epss 0.00
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
- risk 0.33cvss 5.0epss 0.01
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- risk 0.32cvss 4.9epss 0.01
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
- risk 0.32cvss 4.9epss 0.01
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
- risk 0.32cvss 4.9epss 0.01
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
- risk 0.31cvss 4.7epss 0.01
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
- risk 0.31cvss 4.8epss 0.00
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
- risk 0.29cvss 4.4epss 0.00
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
- risk 0.29cvss 4.4epss 0.00
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
- risk 0.29cvss 4.4epss 0.00
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
- risk 0.29cvss 4.5epss 0.00
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
- risk 0.29cvss 4.4epss 0.00
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
- risk 0.29cvss 4.4epss 0.00
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
- risk 0.28cvss 4.3epss 0.00
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
- risk 0.28cvss 4.3epss 0.01
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
- risk 0.28cvss 4.3epss 0.01
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
Page 16 of 22