VYPR

Vendor CVEs

CPanel

All CVEs

446 total · sorted by risk
  • CVE-2020-26103HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).

  • CVE-2020-26102HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

  • CVE-2020-26099HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).

  • CVE-2016-10803HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).

  • CVE-2016-10790HigAug 6, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).

  • CVE-2017-18476HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.01

    Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).

  • CVE-2017-18462HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).

  • CVE-2017-18431HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

  • CVE-2017-18406HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

  • CVE-2016-10833HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

  • CVE-2016-10837HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

  • CVE-2015-9291HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

  • CVE-2019-14388HigJul 30, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).

  • CVE-2017-18435HigAug 2, 2019
    risk 0.48cvss 7.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

  • CVE-2017-18414HigAug 2, 2019
    risk 0.48cvss 7.4epss 0.01

    cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

  • CVE-2018-20914HigAug 1, 2019
    risk 0.48cvss 7.3epss 0.01

    In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).

  • CVE-2021-38585HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).

  • CVE-2021-38584HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

  • CVE-2020-10120HigMar 17, 2020
    risk 0.47cvss 7.2epss 0.03

    cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).

  • CVE-2020-10115HigMar 17, 2020
    risk 0.47cvss 7.2epss 0.02

    cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).

  • CVE-2017-18387HigAug 2, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

  • CVE-2017-18386HigAug 2, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

  • CVE-2016-10831HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).

  • CVE-2016-10848HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).

  • CVE-2018-20911HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).

  • CVE-2018-20895HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

  • CVE-2026-32991HigMay 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

  • CVE-2018-20909HigAug 1, 2019
    risk 0.46cvss 7.1epss 0.00

    cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).

  • CVE-2019-14399HigJul 30, 2019
    risk 0.46cvss 7.1epss 0.00

    The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).

  • CVE-2016-10798MedAug 7, 2019
    risk 0.44cvss 6.8epss 0.01

    cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).

  • CVE-2017-18452MedAug 2, 2019
    risk 0.44cvss 6.7epss 0.00

    cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).

  • CVE-2017-18411MedAug 2, 2019
    risk 0.44cvss 6.8epss 0.01

    The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).

  • CVE-2018-20926MedAug 1, 2019
    risk 0.44cvss 6.7epss 0.00

    cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).

  • CVE-2018-20925MedAug 1, 2019
    risk 0.44cvss 6.7epss 0.00

    cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).

  • CVE-2018-20882MedAug 1, 2019
    risk 0.44cvss 6.8epss 0.00

    cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).

  • CVE-2012-6448MedJan 27, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-9516HigJun 3, 2026
    risk 0.42cvss 7.5epss 0.00

    Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it…

  • CVE-2020-29136MedNov 27, 2020
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

  • CVE-2020-10122MedMar 17, 2020
    risk 0.42cvss 6.5epss 0.01

    cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).

  • CVE-2019-20495MedMar 17, 2020
    risk 0.42cvss 6.5epss 0.01

    cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).

  • CVE-2016-10807MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).

  • CVE-2016-10794MedAug 6, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).

  • CVE-2016-10786MedAug 6, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).

  • CVE-2016-10785MedAug 6, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).

  • CVE-2017-18482MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).

  • CVE-2017-18480MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).

  • CVE-2017-18479MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.00

    In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

  • CVE-2017-18478MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).

  • CVE-2017-18477MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).

  • CVE-2017-18474MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).

Page 3 of 9