Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20908 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). | ||
| CVE-2018-20902 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | ||
| CVE-2018-20891 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436). | ||
| CVE-2018-20888 | Med | 0.36 | 5.5 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). | ||
| CVE-2019-14409 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | ||
| CVE-2019-14404 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). | ||
| CVE-2019-14394 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489). | ||
| CVE-2018-20870 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2019 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | ||
| CVE-2004-1603 | Med | 0.36 | 5.5 | 0.02 | Oct 18, 2004 | cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled. | ||
| CVE-2025-43920 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to… | ||
| CVE-2020-12784 | Med | 0.35 | 5.3 | 0.01 | May 11, 2020 | cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505). | ||
| CVE-2020-10116 | Med | 0.35 | 5.3 | 0.01 | Mar 17, 2020 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541). | ||
| CVE-2019-20497 | Med | 0.35 | 5.4 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). | ||
| CVE-2019-20491 | Med | 0.35 | 5.4 | 0.01 | Mar 16, 2020 | cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508). | ||
| CVE-2012-6449 | Med | 0.35 | 5.4 | 0.01 | Feb 10, 2020 | The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | ||
| CVE-2016-10806 | Med | 0.35 | 5.4 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110). | ||
| CVE-2016-10791 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2019 | cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559). | ||
| CVE-2016-10784 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184). | ||
| CVE-2016-10783 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182). | ||
| CVE-2016-10782 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181). | ||
| CVE-2016-10781 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180). | ||
| CVE-2016-10780 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180). | ||
| CVE-2016-10779 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179). | ||
| CVE-2016-10778 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178). | ||
| CVE-2016-10777 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177). | ||
| CVE-2016-10776 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174). | ||
| CVE-2017-18481 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211). | ||
| CVE-2017-18473 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199). | ||
| CVE-2017-18471 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197). | ||
| CVE-2016-10774 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172). | ||
| CVE-2016-10767 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159). | ||
| CVE-2017-18454 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262). | ||
| CVE-2017-18451 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257). | ||
| CVE-2017-18448 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252). | ||
| CVE-2017-18444 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248). | ||
| CVE-2017-18442 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246). | ||
| CVE-2017-18420 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). | ||
| CVE-2017-18419 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). | ||
| CVE-2017-18418 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). | ||
| CVE-2017-18417 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). | ||
| CVE-2017-18408 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). | ||
| CVE-2017-18402 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). | ||
| CVE-2016-10813 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118). | ||
| CVE-2016-10827 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96). | ||
| CVE-2016-10822 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88). | ||
| CVE-2018-20935 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). | ||
| CVE-2018-20933 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). | ||
| CVE-2016-10841 | Med | 0.35 | 5.3 | 0.01 | Aug 1, 2019 | The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). | ||
| CVE-2018-20916 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | ||
| CVE-2018-20915 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). |
- risk 0.36cvss 5.5epss 0.00
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
- risk 0.36cvss 5.5epss 0.00
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
- risk 0.36cvss 5.5epss 0.00
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
- risk 0.36cvss 5.5epss 0.00
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
- risk 0.36cvss 5.5epss 0.00
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
- risk 0.36cvss 5.5epss 0.00
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
- risk 0.36cvss 5.5epss 0.00
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
- risk 0.36cvss 5.5epss 0.00
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
- risk 0.36cvss 5.5epss 0.02
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
- risk 0.35cvss 5.4epss 0.01
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to…
- risk 0.35cvss 5.3epss 0.01
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
- risk 0.35cvss 5.3epss 0.01
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
- risk 0.35cvss 5.4epss 0.01
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
- risk 0.35cvss 5.4epss 0.01
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
- risk 0.35cvss 5.3epss 0.01
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
- risk 0.35cvss 5.4epss 0.01
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
- risk 0.35cvss 5.4epss 0.01
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
- risk 0.35cvss 5.4epss 0.01
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
- risk 0.35cvss 5.4epss 0.01
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
- risk 0.35cvss 5.4epss 0.01
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
- risk 0.35cvss 5.4epss 0.01
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
- risk 0.35cvss 5.4epss 0.01
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
- risk 0.35cvss 5.4epss 0.01
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
- risk 0.35cvss 5.3epss 0.01
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
- risk 0.35cvss 5.4epss 0.01
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
Page 6 of 9