Plesk
Products
14- 19 CVEs
- 10 CVEs
- 8 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68488 | Cri | 0.64 | 9.9 | 0.00 | Sep 10, 2026 | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover. | ||
| CVE-2026-68487 | Cri | 0.64 | 9.9 | 0.01 | Sep 10, 2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | ||
| CVE-2026-65646 | Cri | 0.64 | 9.9 | 0.01 | Aug 26, 2026 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. | ||
| CVE-2026-64637 | Cri | 0.64 | 9.9 | 0.00 | Aug 7, 2026 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. | ||
| CVE-2026-58046 | Cri | 0.64 | 9.9 | 0.01 | Jul 30, 2026 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. | ||
| CVE-2026-48614 | Cri | 0.64 | 9.9 | 0.01 | Jul 6, 2026 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server. | ||
| CVE-2026-44962 | Cri | 0.64 | 9.9 | 0.01 | May 29, 2026 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system… | ||
| CVE-2025-54336 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2025 | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php. | ||
| CVE-2026-87898 | Cri | 0.61 | — | 0.01 | Sep 23, 2026 | OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges. | ||
| CVE-2026-64639 | Cri | 0.60 | — | 0.01 | Aug 12, 2026 | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator. | ||
| CVE-2026-67394 | Cri | 0.59 | — | 0.01 | Sep 1, 2026 | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their… | ||
| CVE-2025-66430 | Cri | 0.59 | 9.1 | 0.01 | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. | ||
| CVE-2026-68492 | Hig | 0.57 | — | 0.00 | Sep 23, 2026 | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7. | ||
| CVE-2026-68489 | Hig | 0.57 | — | 0.01 | Sep 14, 2026 | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables. | ||
| CVE-2026-65647 | Hig | 0.57 | — | 0.01 | Aug 26, 2026 | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | ||
| CVE-2023-0829 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription. | ||
| CVE-2021-45008 | Hig | 0.57 | 8.8 | 0.02 | Feb 21, 2022 | Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users | ||
| CVE-2026-65642 | Hig | 0.56 | — | 0.00 | Aug 26, 2026 | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. | ||
| CVE-2026-67397 | Hig | 0.55 | — | 0.00 | Sep 4, 2026 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | ||
| CVE-2026-64636 | Hig | 0.50 | 7.7 | 0.00 | Aug 7, 2026 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database. |
- risk 0.64cvss 9.9epss 0.00
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
- risk 0.64cvss 9.9epss 0.01
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
- risk 0.64cvss 9.9epss 0.00
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
- risk 0.64cvss 9.9epss 0.01
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
- risk 0.64cvss 9.9epss 0.01
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system…
- risk 0.64cvss 9.8epss 0.01
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.
- risk 0.61cvss —epss 0.01
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
- risk 0.60cvss —epss 0.01
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
- risk 0.59cvss —epss 0.01
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their…
- risk 0.59cvss 9.1epss 0.01
Plesk 18.0 has Incorrect Access Control.
- risk 0.57cvss —epss 0.00
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
- risk 0.57cvss —epss 0.01
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
- risk 0.57cvss —epss 0.01
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
- risk 0.57cvss 8.8epss 0.01
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
- risk 0.57cvss 8.8epss 0.02
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
- risk 0.56cvss —epss 0.00
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
- risk 0.55cvss —epss 0.00
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
- risk 0.50cvss 7.7epss 0.00
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.