VYPR

Vendor CVEs

CPanel

All CVEs

446 total · sorted by risk
  • CVE-2018-20905MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).

  • CVE-2016-10854MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).

  • CVE-2016-10853MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).

  • CVE-2016-10851MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

  • CVE-2018-20885MedAug 1, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).

  • CVE-2018-20884MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).

  • CVE-2018-20881MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

  • CVE-2018-20878MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).

  • CVE-2018-20877MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).

  • CVE-2018-20876MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).

  • CVE-2018-20875MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).

  • CVE-2018-20874MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).

  • CVE-2019-14411MedJul 30, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).

  • CVE-2019-14397MedJul 30, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).

  • CVE-2019-14390MedJul 30, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).

  • CVE-2019-14386MedJul 30, 2019
    risk 0.35cvss 5.4epss 0.01

    cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).

  • CVE-2017-11441MedJul 19, 2017
    risk 0.35cvss 5.4epss 0.01

    The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.

  • CVE-2018-20886MedAug 1, 2019
    risk 0.34cvss 5.3epss 0.00

    cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).

  • CVE-2019-14393MedJul 30, 2019
    risk 0.34cvss 5.3epss 0.00

    cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).

  • CVE-2017-18441MedAug 2, 2019
    risk 0.33cvss 5.0epss 0.01

    cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).

  • CVE-2017-18464MedAug 5, 2019
    risk 0.32cvss 4.9epss 0.01

    cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).

  • CVE-2017-18453MedAug 2, 2019
    risk 0.32cvss 4.9epss 0.01

    cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).

  • CVE-2018-20913MedAug 1, 2019
    risk 0.32cvss 4.9epss 0.01

    cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).

  • CVE-2017-18430MedAug 2, 2019
    risk 0.31cvss 4.7epss 0.01

    In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).

  • CVE-2017-18407MedAug 2, 2019
    risk 0.31cvss 4.8epss 0.00

    cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).

  • CVE-2025-40929MedSep 8, 2025
    risk 0.29cvss 5.6epss 0.00

    Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

  • CVE-2021-38586MedAug 11, 2021
    risk 0.29cvss 4.4epss 0.00

    In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).

  • CVE-2017-18465MedAug 5, 2019
    risk 0.29cvss 4.4epss 0.00

    cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).

  • CVE-2017-18457MedAug 2, 2019
    risk 0.29cvss 4.4epss 0.00

    cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).

  • CVE-2017-18450MedAug 2, 2019
    risk 0.29cvss 4.5epss 0.00

    cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).

  • CVE-2017-18437MedAug 2, 2019
    risk 0.29cvss 4.4epss 0.00

    cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).

  • CVE-2018-20889MedAug 1, 2019
    risk 0.29cvss 4.4epss 0.00

    cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).

  • CVE-2016-10797MedAug 6, 2019
    risk 0.28cvss 4.3epss 0.00

    cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).

  • CVE-2017-18467MedAug 5, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).

  • CVE-2017-18461MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).

  • CVE-2017-18445MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).

  • CVE-2017-18440MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).

  • CVE-2018-20937MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).

  • CVE-2016-10835MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).

  • CVE-2018-20907MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).

  • CVE-2018-20906MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).

  • CVE-2018-20904MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).

  • CVE-2018-20898MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

  • CVE-2018-20892MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).

  • CVE-2018-20890MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).

  • CVE-2019-14413MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

  • CVE-2019-14408MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

  • CVE-2019-14403MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

  • CVE-2020-29135MedNov 27, 2020
    risk 0.27cvss 4.1epss 0.01

    cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).

  • CVE-2017-18398LowAug 2, 2019
    risk 0.25cvss 3.8epss 0.01

    DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).

Page 7 of 9