CPanel
cPanel is a web hosting control panel software developed by cPanel, L.L.C. It provides a graphical interface (GUI) and automation tools designed to simplify the process of hosting a web site for the website owner or "end user". It enables administration through a standard web browser using a three-tier structure. While cPanel is limited to managing a single hosting account, cPanel & WHM allow the administration of the entire server.
Products
67- 427 CVEs
- 34 CVEs
- 7 CVEs
- 6 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- View all 67 products →
Recent CVEs
451| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41940 | Cri | 0.93 | 9.8 | 0.99 | KEV | Apr 29, 2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| CVE-2026-67401 | Cri | 0.64 | 9.9 | 0.01 | Sep 9, 2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | ||
| CVE-2026-47365 | Cri | 0.64 | 9.9 | 0.01 | Jun 12, 2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | ||
| CVE-2020-26108 | Cri | 0.64 | 9.8 | 0.02 | Sep 25, 2020 | cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). | ||
| CVE-2020-26105 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). | ||
| CVE-2020-26101 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). | ||
| CVE-2020-26100 | Cri | 0.64 | 9.8 | 0.02 | Sep 25, 2020 | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). | ||
| CVE-2020-26098 | Cri | 0.64 | 9.8 | 0.03 | Sep 25, 2020 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). | ||
| CVE-2020-10121 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). | ||
| CVE-2020-10119 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). | ||
| CVE-2019-20498 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534). | ||
| CVE-2016-10817 | Cri | 0.64 | 9.8 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123). | ||
| CVE-2016-10824 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90). | ||
| CVE-2016-10858 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). | ||
| CVE-2016-10855 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). | ||
| CVE-2018-20887 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | ||
| CVE-2018-20863 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2019 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | ||
| CVE-2026-87900 | Cri | 0.61 | — | 0.01 | Sep 23, 2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. | ||
| CVE-2026-87899 | Cri | 0.61 | — | 0.01 | Sep 23, 2026 | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges. | ||
| CVE-2026-58048 | Cri | 0.61 | — | 0.01 | Jul 31, 2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. |
- risk 0.93cvss 9.8epss 0.99
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- risk 0.64cvss 9.9epss 0.01
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
- risk 0.64cvss 9.9epss 0.01
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
- risk 0.64cvss 9.8epss 0.02
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
- risk 0.64cvss 9.8epss 0.01
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
- risk 0.64cvss 9.8epss 0.01
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
- risk 0.64cvss 9.8epss 0.02
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
- risk 0.64cvss 9.8epss 0.03
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
- risk 0.64cvss 9.8epss 0.02
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
- risk 0.64cvss 9.8epss 0.02
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
- risk 0.64cvss 9.8epss 0.02
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
- risk 0.64cvss 9.8epss 0.02
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
- risk 0.64cvss 9.8epss 0.03
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
- risk 0.64cvss 9.8epss 0.03
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
- risk 0.64cvss 9.8epss 0.03
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
- risk 0.64cvss 9.8epss 0.01
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
- risk 0.64cvss 9.8epss 0.02
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
- risk 0.61cvss —epss 0.01
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
- risk 0.61cvss —epss 0.01
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
- risk 0.61cvss —epss 0.01
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.