VYPR

Cpanel

by CPanel

CVEs (427)

  • CVE-2020-10117CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).

  • CVE-2026-65643HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

  • CVE-2025-66429HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

  • CVE-2019-20492HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).

  • CVE-2019-20490HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).

  • CVE-2019-17375HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).

  • CVE-2016-10812HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).

  • CVE-2016-10811HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).

  • CVE-2016-10810HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).

  • CVE-2016-10809HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).

  • CVE-2016-10808HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).

  • CVE-2016-10805HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).

  • CVE-2016-10802HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).

  • CVE-2016-10801HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 58.0.4 has improper session handling for shared users (SEC-139).

  • CVE-2016-10793HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).

  • CVE-2016-10792HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

  • CVE-2016-10789HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).

  • CVE-2016-10788HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).

  • CVE-2017-18475HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).

  • CVE-2017-18470HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).

Page 2 of 22