Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41940 | Cri | 0.93 | 9.8 | 0.98 | KEV | Apr 29, 2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| CVE-2026-47365 | Cri | 0.64 | 9.9 | 0.00 | Jun 12, 2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | ||
| CVE-2020-26108 | Cri | 0.64 | 9.8 | 0.02 | Sep 25, 2020 | cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). | ||
| CVE-2020-26105 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). | ||
| CVE-2020-26101 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). | ||
| CVE-2020-26100 | Cri | 0.64 | 9.8 | 0.02 | Sep 25, 2020 | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). | ||
| CVE-2020-26098 | Cri | 0.64 | 9.8 | 0.03 | Sep 25, 2020 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). | ||
| CVE-2020-10121 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546). | ||
| CVE-2020-10119 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). | ||
| CVE-2019-20498 | Cri | 0.64 | 9.8 | 0.02 | Mar 17, 2020 | cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534). | ||
| CVE-2016-10817 | Cri | 0.64 | 9.8 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123). | ||
| CVE-2016-10824 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90). | ||
| CVE-2016-10858 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). | ||
| CVE-2016-10855 | Cri | 0.64 | 9.8 | 0.03 | Aug 1, 2019 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). | ||
| CVE-2018-20887 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | ||
| CVE-2018-20863 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2019 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | ||
| CVE-2026-58048 | Cri | 0.61 | — | 0.01 | Jul 31, 2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | ||
| CVE-2006-5014 | Hig | 0.61 | 8.8 | 0.04 | Sep 27, 2006 | Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin. | ||
| CVE-2020-10118 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). | ||
| CVE-2020-10117 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). | ||
| CVE-2026-29203 | Hig | 0.57 | 8.8 | 0.00 | May 8, 2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled… | ||
| CVE-2026-29202 | Hig | 0.57 | 8.8 | 0.01 | May 8, 2026 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user. | ||
| CVE-2025-66429 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2025 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user. | ||
| CVE-2019-20492 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516). | ||
| CVE-2019-20490 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499). | ||
| CVE-2019-17375 | Hig | 0.57 | 8.8 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517). | ||
| CVE-2016-10812 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117). | ||
| CVE-2016-10811 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116). | ||
| CVE-2016-10810 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115). | ||
| CVE-2016-10809 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114). | ||
| CVE-2016-10808 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). | ||
| CVE-2016-10805 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). | ||
| CVE-2016-10802 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). | ||
| CVE-2016-10801 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 has improper session handling for shared users (SEC-139). | ||
| CVE-2016-10793 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). | ||
| CVE-2016-10792 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). | ||
| CVE-2016-10789 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). | ||
| CVE-2016-10788 | Hig | 0.57 | 8.8 | 0.02 | Aug 6, 2019 | cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). | ||
| CVE-2017-18475 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204). | ||
| CVE-2017-18470 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196). | ||
| CVE-2016-10773 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171). | ||
| CVE-2017-18433 | Hig | 0.57 | 8.8 | 0.02 | Aug 2, 2019 | cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236). | ||
| CVE-2016-10826 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). | ||
| CVE-2016-10820 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). | ||
| CVE-2016-10816 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121). | ||
| CVE-2016-10814 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119). | ||
| CVE-2016-10834 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105). | ||
| CVE-2016-10828 | Hig | 0.57 | 8.8 | 0.03 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97). | ||
| CVE-2016-10823 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89). | ||
| CVE-2016-10840 | Hig | 0.57 | 8.8 | 0.02 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). |
- risk 0.93cvss 9.8epss 0.98
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- risk 0.64cvss 9.9epss 0.00
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
- risk 0.64cvss 9.8epss 0.02
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
- risk 0.64cvss 9.8epss 0.01
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
- risk 0.64cvss 9.8epss 0.01
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
- risk 0.64cvss 9.8epss 0.02
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
- risk 0.64cvss 9.8epss 0.03
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
- risk 0.64cvss 9.8epss 0.02
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
- risk 0.64cvss 9.8epss 0.02
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
- risk 0.64cvss 9.8epss 0.02
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
- risk 0.64cvss 9.8epss 0.02
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
- risk 0.64cvss 9.8epss 0.03
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
- risk 0.64cvss 9.8epss 0.03
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
- risk 0.64cvss 9.8epss 0.03
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
- risk 0.64cvss 9.8epss 0.01
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
- risk 0.64cvss 9.8epss 0.02
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
- risk 0.61cvss —epss 0.01
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
- risk 0.61cvss 8.8epss 0.04
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
- risk 0.59cvss 9.1epss 0.01
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
- risk 0.59cvss 9.1epss 0.01
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
- risk 0.57cvss 8.8epss 0.00
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled…
- risk 0.57cvss 8.8epss 0.01
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
- risk 0.57cvss 8.8epss 0.01
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
- risk 0.57cvss 8.8epss 0.01
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
- risk 0.57cvss 8.8epss 0.02
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
- risk 0.57cvss 8.8epss 0.01
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
- risk 0.57cvss 8.8epss 0.01
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
- risk 0.57cvss 8.8epss 0.02
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
- risk 0.57cvss 8.8epss 0.02
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
- risk 0.57cvss 8.8epss 0.01
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
- risk 0.57cvss 8.8epss 0.03
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
- risk 0.57cvss 8.8epss 0.02
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
- risk 0.57cvss 8.8epss 0.02
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
Page 1 of 9