VYPR
Vendor

Plesk

Products
14
CVEs
34
Across products
49
Status
Private

Products

14

Recent CVEs

34
View all 34 CVEs →
  • CVE-2026-68488CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

  • CVE-2026-68487CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.01

    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

  • CVE-2026-65646CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

  • CVE-2026-64637CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

  • CVE-2026-58046CriJul 30, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

  • CVE-2026-48614CriJul 6, 2026
    risk 0.64cvss 9.9epss 0.01

    An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

  • CVE-2026-44962CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system…

  • CVE-2025-54336CriAug 19, 2025
    risk 0.64cvss 9.8epss 0.01

    In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

  • CVE-2026-87898CriSep 23, 2026
    risk 0.61cvss —epss 0.01

    OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

  • CVE-2026-64639CriAug 12, 2026
    risk 0.60cvss —epss 0.01

    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

  • CVE-2026-67394CriSep 1, 2026
    risk 0.59cvss —epss 0.01

    A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their…

  • CVE-2025-66430CriDec 12, 2025
    risk 0.59cvss 9.1epss 0.01

    Plesk 18.0 has Incorrect Access Control.

  • CVE-2026-68492HigSep 23, 2026
    risk 0.57cvss —epss 0.00

    An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

  • CVE-2026-68489HigSep 14, 2026
    risk 0.57cvss —epss 0.01

    Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

  • CVE-2026-65647HigAug 26, 2026
    risk 0.57cvss —epss 0.01

    Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

  • CVE-2023-0829HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

  • CVE-2021-45008HigFeb 21, 2022
    risk 0.57cvss 8.8epss 0.02

    Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

  • CVE-2026-65642HigAug 26, 2026
    risk 0.56cvss —epss 0.00

    Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

  • CVE-2026-67397HigSep 4, 2026
    risk 0.55cvss —epss 0.00

    Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

  • CVE-2026-64636HigAug 7, 2026
    risk 0.50cvss 7.7epss 0.00

    An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.