Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10820 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). | ||
| CVE-2016-10816 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121). | ||
| CVE-2016-10814 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119). | ||
| CVE-2016-10834 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105). | ||
| CVE-2016-10828 | Hig | 0.57 | 8.8 | 0.03 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97). | ||
| CVE-2016-10823 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89). | ||
| CVE-2016-10840 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). | ||
| CVE-2016-10850 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83). | ||
| CVE-2019-14405 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | ||
| CVE-2019-14401 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480). | ||
| CVE-2019-14398 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498). | ||
| CVE-2019-14392 | Hig | 0.57 | 8.8 | 0.02 | Jul 30, 2019 | cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). | ||
| CVE-2026-29205 | Hig | 0.56 | 8.6 | 0.08 | May 13, 2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | ||
| CVE-2026-29206 | Hig | 0.53 | 8.1 | 0.00 | May 13, 2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | ||
| CVE-2026-32992 | Hig | 0.53 | 8.2 | 0.00 | May 13, 2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | ||
| CVE-2021-38589 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2021 | In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588). | ||
| CVE-2021-38588 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2021 | In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587). | ||
| CVE-2020-12785 | Hig | 0.53 | 8.1 | 0.01 | May 11, 2020 | cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540). | ||
| CVE-2016-10804 | Hig | 0.53 | 8.1 | 0.01 | Aug 7, 2019 | The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58). | ||
| CVE-2016-10787 | Hig | 0.53 | 8.1 | 0.01 | Aug 6, 2019 | The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187). |
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
- risk 0.57cvss 8.8epss 0.02
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
- risk 0.57cvss 8.8epss 0.01
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
- risk 0.57cvss 8.8epss 0.03
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
- risk 0.57cvss 8.8epss 0.02
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
- risk 0.57cvss 8.8epss 0.02
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
- risk 0.57cvss 8.8epss 0.02
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
- risk 0.57cvss 8.8epss 0.01
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
- risk 0.57cvss 8.8epss 0.01
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
- risk 0.57cvss 8.8epss 0.01
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
- risk 0.57cvss 8.8epss 0.02
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
- risk 0.56cvss 8.6epss 0.08
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
- risk 0.53cvss 8.1epss 0.00
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
- risk 0.53cvss 8.2epss 0.00
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
- risk 0.53cvss 8.1epss 0.01
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
- risk 0.53cvss 8.1epss 0.00
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
- risk 0.53cvss 8.1epss 0.01
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
- risk 0.53cvss 8.1epss 0.01
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
- risk 0.53cvss 8.1epss 0.01
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
Page 3 of 22