VYPR

Vendor CVEs

CPanel

All CVEs

446 total · sorted by risk
  • CVE-2026-41940CriKEVApr 29, 2026
    risk 0.93cvss 9.8epss 0.98

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  • CVE-2026-47365CriJun 12, 2026
    risk 0.64cvss 9.9epss 0.00

    Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

  • CVE-2020-26108CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

  • CVE-2020-26105CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

  • CVE-2020-26101CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

  • CVE-2020-26100CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.02

    chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

  • CVE-2020-26098CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.03

    cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

  • CVE-2020-10121CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).

  • CVE-2020-10119CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

  • CVE-2019-20498CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

  • CVE-2016-10817CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

  • CVE-2016-10824CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

  • CVE-2016-10858CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

  • CVE-2016-10855CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

  • CVE-2018-20887CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.01

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

  • CVE-2018-20863CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

  • CVE-2026-58048CriJul 31, 2026
    risk 0.61cvss epss 0.01

    Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

  • CVE-2006-5014HigSep 27, 2006
    risk 0.61cvss 8.8epss 0.04

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.

  • CVE-2020-10118CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).

  • CVE-2020-10117CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).

  • CVE-2026-29203HigMay 8, 2026
    risk 0.57cvss 8.8epss 0.00

    A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled…

  • CVE-2026-29202HigMay 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

  • CVE-2025-66429HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

  • CVE-2019-20492HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).

  • CVE-2019-20490HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).

  • CVE-2019-17375HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).

  • CVE-2016-10812HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).

  • CVE-2016-10811HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).

  • CVE-2016-10810HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).

  • CVE-2016-10809HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).

  • CVE-2016-10808HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).

  • CVE-2016-10805HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).

  • CVE-2016-10802HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).

  • CVE-2016-10801HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 58.0.4 has improper session handling for shared users (SEC-139).

  • CVE-2016-10793HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).

  • CVE-2016-10792HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

  • CVE-2016-10789HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).

  • CVE-2016-10788HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).

  • CVE-2017-18475HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).

  • CVE-2017-18470HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).

  • CVE-2016-10773HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).

  • CVE-2017-18433HigAug 2, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).

  • CVE-2016-10826HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

  • CVE-2016-10820HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

  • CVE-2016-10816HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).

  • CVE-2016-10814HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

  • CVE-2016-10834HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

  • CVE-2016-10828HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.03

    cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

  • CVE-2016-10823HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

  • CVE-2016-10840HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

Page 1 of 9