Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17377 | Med | 0.40 | 6.1 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). | ||
| CVE-2019-17376 | Med | 0.40 | 6.1 | 0.00 | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). | ||
| CVE-2016-10795 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). | ||
| CVE-2017-18472 | Med | 0.40 | 6.1 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198). | ||
| CVE-2016-10769 | Med | 0.40 | 6.1 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162). | ||
| CVE-2017-18456 | Med | 0.40 | 6.1 | 0.01 | Aug 2, 2019 | cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217). | ||
| CVE-2018-20953 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | ||
| CVE-2018-20951 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). | ||
| CVE-2018-20950 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). | ||
| CVE-2018-20949 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). | ||
| CVE-2018-20948 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). | ||
| CVE-2018-20929 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392). | ||
| CVE-2018-20928 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). | ||
| CVE-2018-20923 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | ||
| CVE-2018-20922 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | ||
| CVE-2018-20921 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | ||
| CVE-2018-20920 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | ||
| CVE-2018-20919 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | ||
| CVE-2018-20918 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | ||
| CVE-2018-20910 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | ||
| CVE-2018-20903 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421). | ||
| CVE-2018-20901 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). | ||
| CVE-2018-20900 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). | ||
| CVE-2018-20899 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | ||
| CVE-2019-14406 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | ||
| CVE-2018-20868 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | ||
| CVE-2018-20866 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | ||
| CVE-2018-20865 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | ||
| CVE-2018-20867 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | ||
| CVE-2019-14387 | Med | 0.40 | 6.1 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). | ||
| CVE-2018-16236 | Med | 0.40 | 6.1 | 0.01 | Aug 30, 2018 | cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering. | ||
| CVE-2017-5616 | Med | 0.40 | 6.1 | 0.01 | Mar 3, 2017 | Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter. | ||
| CVE-2017-5615 | Med | 0.40 | 6.1 | 0.01 | Mar 3, 2017 | cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location. | ||
| CVE-2017-5614 | Med | 0.40 | 6.1 | 0.01 | Mar 3, 2017 | Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter. | ||
| CVE-2025-43919 | Med | 0.38 | 5.8 | 0.01 | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report… | ||
| CVE-2017-18443 | Med | 0.38 | 5.8 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247). | ||
| CVE-2018-20945 | Med | 0.37 | 5.7 | 0.01 | Aug 1, 2019 | bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). | ||
| CVE-2026-58047 | Med | 0.36 | — | 0.01 | Jul 31, 2026 | HTTP Smuggling in cPanel allows potential leak of credentials. | ||
| CVE-2021-38590 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2021 | In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584). | ||
| CVE-2019-20496 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). | ||
| CVE-2016-10799 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2019 | cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). | ||
| CVE-2017-18449 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254). | ||
| CVE-2017-18416 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). | ||
| CVE-2017-18405 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). | ||
| CVE-2017-18396 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329). | ||
| CVE-2017-18385 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). | ||
| CVE-2018-20947 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). | ||
| CVE-2018-20941 | Med | 0.36 | 5.6 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). | ||
| CVE-2018-20924 | Med | 0.36 | 5.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). | ||
| CVE-2018-20917 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 70.0.23 allows any user to disable Solr (SEC-371). |
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
- risk 0.40cvss 6.1epss 0.00
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
- risk 0.40cvss 6.1epss 0.01
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
- risk 0.40cvss 6.1epss 0.01
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
- risk 0.40cvss 6.1epss 0.01
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- risk 0.40cvss 6.1epss 0.01
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
- risk 0.40cvss 6.1epss 0.01
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
- risk 0.40cvss 6.1epss 0.01
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
- risk 0.40cvss 6.1epss 0.01
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
- risk 0.40cvss 6.1epss 0.01
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
- risk 0.40cvss 6.1epss 0.01
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
- risk 0.40cvss 6.1epss 0.01
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
- risk 0.40cvss 6.1epss 0.01
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.
- risk 0.40cvss 6.1epss 0.01
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
- risk 0.38cvss 5.8epss 0.01
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report…
- risk 0.38cvss 5.8epss 0.01
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
- risk 0.37cvss 5.7epss 0.01
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
- risk 0.36cvss —epss 0.01
HTTP Smuggling in cPanel allows potential leak of credentials.
- risk 0.36cvss 5.5epss 0.00
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
- risk 0.36cvss 5.5epss 0.00
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
- risk 0.36cvss 5.5epss 0.00
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
- risk 0.36cvss 5.5epss 0.00
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
- risk 0.36cvss 5.5epss 0.00
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
- risk 0.36cvss 5.6epss 0.00
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
- risk 0.36cvss 5.5epss 0.01
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
- risk 0.36cvss 5.5epss 0.00
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
Page 5 of 9