VYPR

Vendor CVEs

CPanel

All CVEs

446 total · sorted by risk
  • CVE-2016-10775MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).

  • CVE-2016-10770MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).

  • CVE-2016-10768MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

  • CVE-2017-18410MedAug 2, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).

  • CVE-2017-18409MedAug 2, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).

  • CVE-2016-10821MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).

  • CVE-2016-10819MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).

  • CVE-2016-10818MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.02

    cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).

  • CVE-2016-10815MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).

  • CVE-2018-20952MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).

  • CVE-2016-10832MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).

  • CVE-2016-10829MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

  • CVE-2018-20934MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).

  • CVE-2018-20930MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).

  • CVE-2016-10849MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).

  • CVE-2016-10844MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).

  • CVE-2016-10842MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).

  • CVE-2016-10838MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).

  • CVE-2016-10836MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).

  • CVE-2016-10857MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

  • CVE-2016-10856MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

  • CVE-2016-10852MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

  • CVE-2018-20883MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

  • CVE-2018-20864MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

  • CVE-2017-18469MedAug 5, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).

  • CVE-2017-18468MedAug 5, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).

  • CVE-2017-18447MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).

  • CVE-2017-18446MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).

  • CVE-2017-18439MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

  • CVE-2017-18438MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

  • CVE-2017-18403MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

  • CVE-2017-18389MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

  • CVE-2018-20931MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

  • CVE-2018-20912MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).

  • CVE-2018-20879MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

  • CVE-2026-9334HigJun 3, 2026
    risk 0.40cvss 7.3epss 0.00

    Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE…

  • CVE-2023-29489MedApr 27, 2023
    risk 0.40cvss 5.3epss 0.66

    An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

  • CVE-2021-31803MedApr 26, 2021
    risk 0.40cvss 6.1epss 0.01

    cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).

  • CVE-2020-29137MedNov 27, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).

  • CVE-2020-26115MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).

  • CVE-2020-26114MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).

  • CVE-2020-26113MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).

  • CVE-2020-26111MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).

  • CVE-2020-26110MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).

  • CVE-2020-10114MedMar 17, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).

  • CVE-2020-10113MedMar 17, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).

  • CVE-2019-20493MedMar 17, 2020
    risk 0.40cvss 6.1epss 0.01

    cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).

  • CVE-2019-17380MedOct 9, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).

  • CVE-2019-17379MedOct 9, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).

  • CVE-2019-17378MedOct 9, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).

Page 4 of 9