Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10775 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173). | ||
| CVE-2016-10770 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164). | ||
| CVE-2016-10768 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161). | ||
| CVE-2017-18410 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284). | ||
| CVE-2017-18409 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283). | ||
| CVE-2016-10821 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75). | ||
| CVE-2016-10819 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125). | ||
| CVE-2016-10818 | Med | 0.42 | 6.5 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124). | ||
| CVE-2016-10815 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120). | ||
| CVE-2018-20952 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388). | ||
| CVE-2016-10832 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). | ||
| CVE-2016-10829 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99). | ||
| CVE-2018-20934 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). | ||
| CVE-2018-20930 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | ||
| CVE-2016-10849 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). | ||
| CVE-2016-10844 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77). | ||
| CVE-2016-10842 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). | ||
| CVE-2016-10838 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | ||
| CVE-2016-10836 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). | ||
| CVE-2016-10857 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). | ||
| CVE-2016-10856 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). | ||
| CVE-2016-10852 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). | ||
| CVE-2018-20883 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | ||
| CVE-2018-20864 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | ||
| CVE-2017-18469 | Med | 0.41 | 6.3 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233). | ||
| CVE-2017-18468 | Med | 0.41 | 6.3 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232). | ||
| CVE-2017-18447 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251). | ||
| CVE-2017-18446 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250). | ||
| CVE-2017-18439 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243). | ||
| CVE-2017-18438 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242). | ||
| CVE-2017-18403 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337). | ||
| CVE-2017-18389 | Med | 0.41 | 6.3 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). | ||
| CVE-2018-20931 | Med | 0.41 | 6.3 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405). | ||
| CVE-2018-20912 | Med | 0.41 | 6.3 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | ||
| CVE-2018-20879 | Med | 0.41 | 6.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | ||
| CVE-2026-9334 | Hig | 0.40 | 7.3 | 0.00 | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE… | ||
| CVE-2023-29489 | Med | 0.40 | 5.3 | 0.66 | Apr 27, 2023 | An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31. | ||
| CVE-2021-31803 | Med | 0.40 | 6.1 | 0.01 | Apr 26, 2021 | cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). | ||
| CVE-2020-29137 | Med | 0.40 | 6.1 | 0.01 | Nov 27, 2020 | cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577). | ||
| CVE-2020-26115 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574). | ||
| CVE-2020-26114 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573). | ||
| CVE-2020-26113 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). | ||
| CVE-2020-26111 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). | ||
| CVE-2020-26110 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564). | ||
| CVE-2020-10114 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). | ||
| CVE-2020-10113 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). | ||
| CVE-2019-20493 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). | ||
| CVE-2019-17380 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | ||
| CVE-2019-17379 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). | ||
| CVE-2019-17378 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). |
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- risk 0.42cvss 6.5epss 0.02
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
- risk 0.42cvss 6.5epss 0.01
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
- risk 0.42cvss 6.5epss 0.01
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
- risk 0.42cvss 6.5epss 0.01
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
- risk 0.42cvss 6.5epss 0.01
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
- risk 0.42cvss 6.5epss 0.01
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
- risk 0.42cvss 6.5epss 0.01
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
- risk 0.42cvss 6.5epss 0.01
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
- risk 0.41cvss 6.3epss 0.01
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
- risk 0.41cvss 6.3epss 0.01
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
- risk 0.41cvss 6.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
- risk 0.41cvss 6.3epss 0.01
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
- risk 0.41cvss 6.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
- risk 0.41cvss 6.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
- risk 0.41cvss 6.3epss 0.01
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
- risk 0.41cvss 6.3epss 0.01
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
- risk 0.41cvss 6.3epss 0.01
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
- risk 0.41cvss 6.3epss 0.01
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
- risk 0.41cvss 6.3epss 0.01
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
- risk 0.40cvss 7.3epss 0.00
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE…
- risk 0.40cvss 5.3epss 0.66
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
- risk 0.40cvss 6.1epss 0.01
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
- risk 0.40cvss 6.1epss 0.01
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
- risk 0.40cvss 6.1epss 0.01
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
- risk 0.40cvss 6.1epss 0.01
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
- risk 0.40cvss 6.1epss 0.01
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
Page 4 of 9