Whm
by CPanel
CVEs (34)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41940 | Cri | 0.93 | 9.8 | 0.98 | KEV | Apr 29, 2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| CVE-2026-29202 | Hig | 0.57 | 8.8 | 0.01 | May 8, 2026 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user. | ||
| CVE-2026-29205 | Hig | 0.56 | 8.6 | 0.07 | May 13, 2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | ||
| CVE-2026-29206 | Hig | 0.53 | 8.1 | 0.00 | May 13, 2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | ||
| CVE-2026-32992 | Hig | 0.53 | 8.2 | 0.00 | May 13, 2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | ||
| CVE-2018-20882 | Med | 0.44 | 6.8 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | ||
| CVE-2017-18482 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). | ||
| CVE-2020-26113 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). | ||
| CVE-2020-26111 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). | ||
| CVE-2019-17380 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | ||
| CVE-2016-10795 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). | ||
| CVE-2018-20953 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | ||
| CVE-2018-20922 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | ||
| CVE-2018-20866 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | ||
| CVE-2012-6449 | Med | 0.35 | 5.4 | 0.01 | Feb 10, 2020 | The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | ||
| CVE-2016-10777 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177). | ||
| CVE-2017-18481 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211). | ||
| CVE-2017-18420 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). | ||
| CVE-2017-18419 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). | ||
| CVE-2017-18417 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). |
- risk 0.93cvss 9.8epss 0.98
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- risk 0.57cvss 8.8epss 0.01
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
- risk 0.56cvss 8.6epss 0.07
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
- risk 0.53cvss 8.1epss 0.00
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
- risk 0.53cvss 8.2epss 0.00
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
- risk 0.44cvss 6.8epss 0.00
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
- risk 0.40cvss 6.1epss 0.01
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
- risk 0.35cvss 5.4epss 0.01
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
Page 1 of 2