VYPR

Vendor CVEs

CPanel

All CVEs

446 total · sorted by risk
  • CVE-2018-20908MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).

  • CVE-2018-20902MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).

  • CVE-2018-20891MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

  • CVE-2018-20888MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

  • CVE-2019-14409MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).

  • CVE-2019-14404MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).

  • CVE-2019-14394MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).

  • CVE-2018-20870MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.00

    The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

  • CVE-2004-1603MedOct 18, 2004
    risk 0.36cvss 5.5epss 0.02

    cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.

  • CVE-2025-43920MedApr 20, 2025
    risk 0.35cvss 5.4epss 0.01

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to…

  • CVE-2020-12784MedMay 11, 2020
    risk 0.35cvss 5.3epss 0.01

    cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).

  • CVE-2020-10116MedMar 17, 2020
    risk 0.35cvss 5.3epss 0.01

    cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).

  • CVE-2019-20497MedMar 17, 2020
    risk 0.35cvss 5.4epss 0.01

    cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).

  • CVE-2019-20491MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).

  • CVE-2012-6449MedFeb 10, 2020
    risk 0.35cvss 5.4epss 0.01

    The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.

  • CVE-2016-10806MedAug 7, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).

  • CVE-2016-10791MedAug 6, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559).

  • CVE-2016-10784MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).

  • CVE-2016-10783MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).

  • CVE-2016-10782MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).

  • CVE-2016-10781MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).

  • CVE-2016-10780MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).

  • CVE-2016-10779MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).

  • CVE-2016-10778MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).

  • CVE-2016-10777MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).

  • CVE-2016-10776MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).

  • CVE-2017-18481MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).

  • CVE-2017-18473MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).

  • CVE-2017-18471MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).

  • CVE-2016-10774MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).

  • CVE-2016-10767MedAug 5, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).

  • CVE-2017-18454MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).

  • CVE-2017-18451MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).

  • CVE-2017-18448MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).

  • CVE-2017-18444MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).

  • CVE-2017-18442MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

  • CVE-2017-18420MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).

  • CVE-2017-18419MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).

  • CVE-2017-18418MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

  • CVE-2017-18417MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

  • CVE-2017-18408MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).

  • CVE-2017-18402MedAug 2, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).

  • CVE-2016-10813MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

  • CVE-2016-10827MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).

  • CVE-2016-10822MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).

  • CVE-2018-20935MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).

  • CVE-2018-20933MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).

  • CVE-2016-10841MedAug 1, 2019
    risk 0.35cvss 5.3epss 0.01

    The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).

  • CVE-2018-20916MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).

  • CVE-2018-20915MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).

Page 6 of 9