Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18462 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224). | ||
| CVE-2017-18431 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2019 | cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941). | ||
| CVE-2017-18406 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276). | ||
| CVE-2016-10833 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). | ||
| CVE-2016-10837 | Hig | 0.49 | 7.5 | 0.02 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). | ||
| CVE-2015-9291 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2019 | cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). | ||
| CVE-2019-14388 | Hig | 0.49 | 7.5 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). | ||
| CVE-2017-18435 | Hig | 0.48 | 7.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238). | ||
| CVE-2017-18414 | Hig | 0.48 | 7.4 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300). | ||
| CVE-2018-20914 | Hig | 0.48 | 7.3 | 0.01 | Aug 1, 2019 | In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | ||
| CVE-2021-38585 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2021 | The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585). | ||
| CVE-2021-38584 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2021 | The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585). | ||
| CVE-2020-10120 | Hig | 0.47 | 7.2 | 0.03 | Mar 17, 2020 | cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). | ||
| CVE-2020-10115 | Hig | 0.47 | 7.2 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). | ||
| CVE-2017-18387 | Hig | 0.47 | 7.2 | 0.02 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). | ||
| CVE-2017-18386 | Hig | 0.47 | 7.2 | 0.02 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). | ||
| CVE-2016-10831 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). | ||
| CVE-2016-10848 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81). | ||
| CVE-2018-20911 | Hig | 0.47 | 7.2 | 0.02 | Aug 1, 2019 | cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | ||
| CVE-2018-20895 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). |
- risk 0.49cvss 7.5epss 0.01
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
- risk 0.49cvss 7.5epss 0.01
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
- risk 0.49cvss 7.5epss 0.01
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
- risk 0.49cvss 7.5epss 0.01
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
- risk 0.49cvss 7.5epss 0.02
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
- risk 0.49cvss 7.5epss 0.01
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
- risk 0.49cvss 7.5epss 0.01
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
- risk 0.48cvss 7.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
- risk 0.48cvss 7.4epss 0.01
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
- risk 0.48cvss 7.3epss 0.01
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
- risk 0.47cvss 7.2epss 0.01
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
- risk 0.47cvss 7.2epss 0.01
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
- risk 0.47cvss 7.2epss 0.03
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
- risk 0.47cvss 7.2epss 0.02
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
- risk 0.47cvss 7.2epss 0.02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
- risk 0.47cvss 7.2epss 0.02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
- risk 0.47cvss 7.2epss 0.01
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
- risk 0.47cvss 7.2epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
- risk 0.47cvss 7.2epss 0.02
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
- risk 0.47cvss 7.2epss 0.01
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
Page 6 of 22