Vendor CVEs
CPanel
All CVEs
446 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20905 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). | ||
| CVE-2016-10854 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). | ||
| CVE-2016-10853 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). | ||
| CVE-2016-10851 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). | ||
| CVE-2018-20885 | Med | 0.35 | 5.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | ||
| CVE-2018-20884 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | ||
| CVE-2018-20881 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | ||
| CVE-2018-20878 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | ||
| CVE-2018-20877 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | ||
| CVE-2018-20876 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | ||
| CVE-2018-20875 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | ||
| CVE-2018-20874 | Med | 0.35 | 5.4 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). | ||
| CVE-2019-14411 | Med | 0.35 | 5.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). | ||
| CVE-2019-14397 | Med | 0.35 | 5.3 | 0.01 | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496). | ||
| CVE-2019-14390 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). | ||
| CVE-2019-14386 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). | ||
| CVE-2017-11441 | Med | 0.35 | 5.4 | 0.01 | Jul 19, 2017 | The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297. | ||
| CVE-2018-20886 | Med | 0.34 | 5.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418). | ||
| CVE-2019-14393 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486). | ||
| CVE-2017-18441 | Med | 0.33 | 5.0 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245). | ||
| CVE-2017-18464 | Med | 0.32 | 4.9 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226). | ||
| CVE-2017-18453 | Med | 0.32 | 4.9 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260). | ||
| CVE-2018-20913 | Med | 0.32 | 4.9 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | ||
| CVE-2017-18430 | Med | 0.31 | 4.7 | 0.01 | Aug 2, 2019 | In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294). | ||
| CVE-2017-18407 | Med | 0.31 | 4.8 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). | ||
| CVE-2025-40929 | Med | 0.29 | 5.6 | 0.00 | Sep 8, 2025 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | ||
| CVE-2021-38586 | Med | 0.29 | 4.4 | 0.00 | Aug 11, 2021 | In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589). | ||
| CVE-2017-18465 | Med | 0.29 | 4.4 | 0.00 | Aug 5, 2019 | cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227). | ||
| CVE-2017-18457 | Med | 0.29 | 4.4 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218). | ||
| CVE-2017-18450 | Med | 0.29 | 4.5 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255). | ||
| CVE-2017-18437 | Med | 0.29 | 4.4 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240). | ||
| CVE-2018-20889 | Med | 0.29 | 4.4 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | ||
| CVE-2016-10797 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2019 | cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133). | ||
| CVE-2017-18467 | Med | 0.28 | 4.3 | 0.01 | Aug 5, 2019 | cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229). | ||
| CVE-2017-18461 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223). | ||
| CVE-2017-18445 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249). | ||
| CVE-2017-18440 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244). | ||
| CVE-2018-20937 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). | ||
| CVE-2016-10835 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107). | ||
| CVE-2018-20907 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). | ||
| CVE-2018-20906 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430). | ||
| CVE-2018-20904 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427). | ||
| CVE-2018-20898 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | ||
| CVE-2018-20892 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439). | ||
| CVE-2018-20890 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426). | ||
| CVE-2019-14413 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | ||
| CVE-2019-14408 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | ||
| CVE-2019-14403 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). | ||
| CVE-2020-29135 | Med | 0.27 | 4.1 | 0.01 | Nov 27, 2020 | cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567). | ||
| CVE-2017-18398 | Low | 0.25 | 3.8 | 0.01 | Aug 2, 2019 | DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331). |
- risk 0.35cvss 5.4epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
- risk 0.35cvss 5.4epss 0.01
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
- risk 0.35cvss 5.3epss 0.01
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
- risk 0.35cvss 5.4epss 0.01
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
- risk 0.35cvss 5.3epss 0.01
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
- risk 0.35cvss 5.3epss 0.01
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
- risk 0.35cvss 5.4epss 0.01
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
- risk 0.35cvss 5.4epss 0.01
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
- risk 0.34cvss 5.3epss 0.00
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
- risk 0.34cvss 5.3epss 0.00
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
- risk 0.33cvss 5.0epss 0.01
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- risk 0.32cvss 4.9epss 0.01
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
- risk 0.32cvss 4.9epss 0.01
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
- risk 0.32cvss 4.9epss 0.01
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
- risk 0.31cvss 4.7epss 0.01
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
- risk 0.31cvss 4.8epss 0.00
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
- risk 0.29cvss 5.6epss 0.00
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
- risk 0.29cvss 4.4epss 0.00
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
- risk 0.29cvss 4.4epss 0.00
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
- risk 0.29cvss 4.4epss 0.00
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
- risk 0.29cvss 4.5epss 0.00
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
- risk 0.29cvss 4.4epss 0.00
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
- risk 0.29cvss 4.4epss 0.00
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
- risk 0.28cvss 4.3epss 0.00
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
- risk 0.28cvss 4.3epss 0.01
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
- risk 0.28cvss 4.3epss 0.01
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
- risk 0.28cvss 4.3epss 0.01
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
- risk 0.28cvss 4.3epss 0.01
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
- risk 0.28cvss 4.3epss 0.01
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
- risk 0.28cvss 4.3epss 0.01
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
- risk 0.28cvss 4.3epss 0.01
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
- risk 0.28cvss 4.3epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
- risk 0.28cvss 4.3epss 0.01
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
- risk 0.27cvss 4.1epss 0.01
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
- risk 0.25cvss 3.8epss 0.01
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
Page 7 of 9