Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26103 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). | ||
| CVE-2020-26102 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550). | ||
| CVE-2020-26099 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491). | ||
| CVE-2016-10803 | Hig | 0.49 | 7.5 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923). | ||
| CVE-2016-10790 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192). | ||
| CVE-2017-18476 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2019 | Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205). | ||
| CVE-2017-18462 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224). | ||
| CVE-2017-18431 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2019 | cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941). | ||
| CVE-2017-18406 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276). | ||
| CVE-2016-10833 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). | ||
| CVE-2016-10837 | Hig | 0.49 | 7.5 | 0.02 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). | ||
| CVE-2015-9291 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2019 | cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). | ||
| CVE-2019-14388 | Hig | 0.49 | 7.5 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). | ||
| CVE-2017-18435 | Hig | 0.48 | 7.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238). | ||
| CVE-2017-18414 | Hig | 0.48 | 7.4 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300). | ||
| CVE-2018-20914 | Hig | 0.48 | 7.3 | 0.01 | Aug 1, 2019 | In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | ||
| CVE-2021-38585 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2021 | The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585). | ||
| CVE-2021-38584 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2021 | The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585). | ||
| CVE-2020-10120 | Hig | 0.47 | 7.2 | 0.03 | Mar 17, 2020 | cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). | ||
| CVE-2020-10115 | Hig | 0.47 | 7.2 | 0.02 | Mar 17, 2020 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). | ||
| CVE-2017-18387 | Hig | 0.47 | 7.2 | 0.02 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). | ||
| CVE-2017-18386 | Hig | 0.47 | 7.2 | 0.02 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). | ||
| CVE-2016-10831 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). | ||
| CVE-2016-10848 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81). | ||
| CVE-2018-20911 | Hig | 0.47 | 7.2 | 0.02 | Aug 1, 2019 | cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | ||
| CVE-2018-20895 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | ||
| CVE-2026-32991 | Hig | 0.46 | 7.1 | 0.00 | May 13, 2026 | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account. | ||
| CVE-2018-20909 | Hig | 0.46 | 7.1 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | ||
| CVE-2019-14399 | Hig | 0.46 | 7.1 | 0.00 | Jul 30, 2019 | The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477). | ||
| CVE-2016-10798 | Med | 0.44 | 6.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134). | ||
| CVE-2017-18452 | Med | 0.44 | 6.7 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259). | ||
| CVE-2017-18411 | Med | 0.44 | 6.8 | 0.01 | Aug 2, 2019 | The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285). | ||
| CVE-2018-20926 | Med | 0.44 | 6.7 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380). | ||
| CVE-2018-20925 | Med | 0.44 | 6.7 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379). | ||
| CVE-2018-20882 | Med | 0.44 | 6.8 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | ||
| CVE-2012-6448 | Med | 0.43 | 6.1 | 0.02 | Jan 27, 2020 | Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2026-9516 | Hig | 0.42 | 7.5 | 0.00 | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it… | ||
| CVE-2020-29136 | Med | 0.42 | 6.5 | 0.01 | Nov 27, 2020 | In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). | ||
| CVE-2020-10122 | Med | 0.42 | 6.5 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547). | ||
| CVE-2019-20495 | Med | 0.42 | 6.5 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531). | ||
| CVE-2016-10807 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). | ||
| CVE-2016-10794 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). | ||
| CVE-2016-10786 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). | ||
| CVE-2016-10785 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). | ||
| CVE-2017-18482 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). | ||
| CVE-2017-18480 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210). | ||
| CVE-2017-18479 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2019 | In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209). | ||
| CVE-2017-18478 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207). | ||
| CVE-2017-18477 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206). | ||
| CVE-2017-18474 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201). |
- risk 0.49cvss 7.5epss 0.01
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
- risk 0.49cvss 7.5epss 0.01
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
- risk 0.49cvss 7.5epss 0.01
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
- risk 0.49cvss 7.5epss 0.01
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
- risk 0.49cvss 7.5epss 0.01
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
- risk 0.49cvss 7.5epss 0.01
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
- risk 0.49cvss 7.5epss 0.01
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
- risk 0.49cvss 7.5epss 0.01
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
- risk 0.49cvss 7.5epss 0.01
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
- risk 0.49cvss 7.5epss 0.01
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
- risk 0.49cvss 7.5epss 0.02
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
- risk 0.49cvss 7.5epss 0.01
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
- risk 0.49cvss 7.5epss 0.01
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
- risk 0.48cvss 7.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
- risk 0.48cvss 7.4epss 0.01
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
- risk 0.48cvss 7.3epss 0.01
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
- risk 0.47cvss 7.2epss 0.01
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
- risk 0.47cvss 7.2epss 0.01
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
- risk 0.47cvss 7.2epss 0.03
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
- risk 0.47cvss 7.2epss 0.02
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
- risk 0.47cvss 7.2epss 0.02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
- risk 0.47cvss 7.2epss 0.02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
- risk 0.47cvss 7.2epss 0.01
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
- risk 0.47cvss 7.2epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
- risk 0.47cvss 7.2epss 0.02
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
- risk 0.47cvss 7.2epss 0.01
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
- risk 0.46cvss 7.1epss 0.00
Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.
- risk 0.46cvss 7.1epss 0.00
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
- risk 0.46cvss 7.1epss 0.00
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
- risk 0.44cvss 6.8epss 0.01
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
- risk 0.44cvss 6.7epss 0.00
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
- risk 0.44cvss 6.8epss 0.01
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
- risk 0.44cvss 6.7epss 0.00
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
- risk 0.44cvss 6.7epss 0.00
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
- risk 0.44cvss 6.8epss 0.00
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
- risk 0.43cvss 6.1epss 0.02
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.42cvss 7.5epss 0.00
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it…
- risk 0.42cvss 6.5epss 0.01
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
- risk 0.42cvss 6.5epss 0.01
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
- risk 0.42cvss 6.5epss 0.01
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
- risk 0.42cvss 6.5epss 0.01
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
- risk 0.42cvss 6.5epss 0.01
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
- risk 0.42cvss 6.5epss 0.00
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
Page 3 of 9