Cpanel
by CPanel
CVEs (413)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20922 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | |||
| CVE-2018-20921 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | |||
| CVE-2018-20920 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | |||
| CVE-2018-20919 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | |||
| CVE-2016-10851 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). | |||
| CVE-2018-20918 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | |||
| CVE-2016-10852 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). | |||
| CVE-2018-20917 | 0.00 | — | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | |||
| CVE-2018-20916 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | |||
| CVE-2018-20915 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | |||
| CVE-2016-10853 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). | |||
| CVE-2018-20914 | 0.00 | — | 0.01 | Aug 1, 2019 | In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | |||
| CVE-2016-10854 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). | |||
| CVE-2018-20913 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | |||
| CVE-2018-20912 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | |||
| CVE-2016-10855 | 0.00 | — | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). | |||
| CVE-2018-20911 | 0.00 | — | 0.02 | Aug 1, 2019 | cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | |||
| CVE-2016-10856 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). | |||
| CVE-2016-10857 | 0.00 | — | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). | |||
| CVE-2016-10858 | 0.00 | — | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). |
- CVE-2018-20922Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
- CVE-2018-20921Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
- CVE-2018-20920Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
- CVE-2018-20919Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
- CVE-2016-10851Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
- CVE-2018-20918Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
- CVE-2016-10852Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
- CVE-2018-20917Aug 1, 2019risk 0.00cvss —epss 0.00
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
- CVE-2018-20916Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
- CVE-2018-20915Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
- CVE-2016-10853Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
- CVE-2018-20914Aug 1, 2019risk 0.00cvss —epss 0.01
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
- CVE-2016-10854Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
- CVE-2018-20913Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
- CVE-2018-20912Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
- CVE-2016-10855Aug 1, 2019risk 0.00cvss —epss 0.03
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
- CVE-2018-20911Aug 1, 2019risk 0.00cvss —epss 0.02
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
- CVE-2016-10856Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
- CVE-2016-10857Aug 1, 2019risk 0.00cvss —epss 0.01
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
- CVE-2016-10858Aug 1, 2019risk 0.00cvss —epss 0.03
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
Page 16 of 21