VYPR

Whm

by CPanel

CVEs (34)

  • CVE-2026-41940CriKEVApr 29, 2026
    risk 0.93cvss 9.8epss 0.98

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  • CVE-2026-29202HigMay 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

  • CVE-2026-29205HigMay 13, 2026
    risk 0.56cvss 8.6epss 0.07

    Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

  • CVE-2026-29206HigMay 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

  • CVE-2026-32992HigMay 13, 2026
    risk 0.53cvss 8.2epss 0.00

    SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

  • CVE-2018-20882MedAug 1, 2019
    risk 0.44cvss 6.8epss 0.00

    cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).

  • CVE-2017-18482MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).

  • CVE-2020-26113MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).

  • CVE-2020-26111MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).

  • CVE-2019-17380MedOct 9, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).

  • CVE-2016-10795MedAug 6, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).

  • CVE-2018-20953MedAug 1, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).

  • CVE-2018-20922MedAug 1, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).

  • CVE-2018-20866MedJul 30, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).

  • CVE-2012-6449MedFeb 10, 2020
    risk 0.35cvss 5.4epss 0.01

    The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.

  • CVE-2016-10777MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).

  • CVE-2017-18481MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).

  • CVE-2017-18420MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).

  • CVE-2017-18419MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).

  • CVE-2017-18417MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

Page 1 of 2