VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2016-10820HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

  • CVE-2016-10816HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).

  • CVE-2016-10814HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

  • CVE-2016-10834HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

  • CVE-2016-10828HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.03

    cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

  • CVE-2016-10823HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

  • CVE-2016-10840HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

  • CVE-2016-10850HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

  • CVE-2019-14405HigJul 30, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

  • CVE-2019-14401HigJul 30, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).

  • CVE-2019-14398HigJul 30, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).

  • CVE-2019-14392HigJul 30, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).

  • CVE-2026-29205HigMay 13, 2026
    risk 0.56cvss 8.6epss 0.08

    Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

  • CVE-2026-29206HigMay 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

  • CVE-2026-32992HigMay 13, 2026
    risk 0.53cvss 8.2epss 0.00

    SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

  • CVE-2021-38589HigAug 11, 2021
    risk 0.53cvss 8.1epss 0.01

    In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).

  • CVE-2021-38588HigAug 11, 2021
    risk 0.53cvss 8.1epss 0.00

    In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).

  • CVE-2020-12785HigMay 11, 2020
    risk 0.53cvss 8.1epss 0.01

    cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).

  • CVE-2016-10804HigAug 7, 2019
    risk 0.53cvss 8.1epss 0.01

    The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).

  • CVE-2016-10787HigAug 6, 2019
    risk 0.53cvss 8.1epss 0.01

    The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).

Page 3 of 22