threat
engine
.sh
Back
·
··:··
Home
/
Product
/
cpanel
Product
cpanel
427 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-41940
>= 11.40 and < 86.0.41
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated r
9.8
CRITICAL
CVE-2025-66429
>= 110.0.0 and < 126.0.37
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for over
8.8
HIGH
CVE-2022-48623
< 4.33
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensiti
9.1
CRITICAL
CVE-2023-29489
< 11.102.0.31
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SE
5.3
MEDIUM
CVE-2021-38590
< 11.98.0.8
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
5.5
MEDIUM
CVE-2021-38589
< 11.96.0.13
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
8.1
HIGH
CVE-2021-38588
< 96.0.13
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
8.1
HIGH
CVE-2021-38587
< 96.0.13
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
7.5
HIGH
CVE-2021-38586
>= 11.94.0.0 and < 11.94.0.13
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
4.4
MEDIUM
CVE-2021-38585
< 98.0.1
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
7.2
HIGH
CVE-2021-38584
< 98.0.1
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
7.2
HIGH
CVE-2021-31803
< 94.0.3
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
6.1
MEDIUM
CVE-2021-26267
< 92.0.9
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
7.5
HIGH
CVE-2021-26266
< 92.0.9
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
7.5
HIGH
CVE-2020-29137
< 90.0.17
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
6.1
MEDIUM
CVE-2020-29136
< 11.86.0.32
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
6.5
MEDIUM
CVE-2020-29135
< 90.0.17
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
4.1
MEDIUM
CVE-2020-26115
< 90.0.10
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
6.1
MEDIUM
CVE-2020-26114
< 90.0.10
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
6.1
MEDIUM
CVE-2020-26113
< 90.0.10
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
6.1
MEDIUM
CVE-2020-26112
< 90.0.10
The email quota cache in cPanel before 90.0.10 allows overwriting of files.
7.5
HIGH
CVE-2020-26111
< 90.0.10
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
6.1
MEDIUM
CVE-2020-26110
< 88.0.13
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
6.1
MEDIUM
CVE-2020-26109
< 88.0.3
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
7.5
HIGH
CVE-2020-26108
< 88.0.13
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
9.8
CRITICAL
CVE-2020-26107
< 88.0.3
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
7.5
HIGH
CVE-2020-26106
< 88.0.3
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
7.5
HIGH
CVE-2020-26105
< 88.0.3
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
9.8
CRITICAL
CVE-2020-26104
< 88.0.3
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
7.5
HIGH
CVE-2020-26103
< 88.0.3
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
7.5
HIGH
CVE-2020-26102
< 88.0.3
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
7.5
HIGH
CVE-2020-26101
< 88.0.3
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
9.8
CRITICAL
CVE-2020-26100
< 88.0.3
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
9.8
CRITICAL
CVE-2020-26099
< 88.0.3
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
7.5
HIGH
CVE-2020-26098
< 88.0.3
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
9.8
CRITICAL
CVE-2020-12785
>= 11.78.0.1 and < 11.78.0.47
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
8.1
HIGH
CVE-2020-12784
>= 11.78.0.1 and < 11.78.0.47
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
5.3
MEDIUM
CVE-2020-10122
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
6.5
MEDIUM
CVE-2020-10121
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
9.8
CRITICAL
CVE-2020-10120
< 84.0.20
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
7.2
HIGH
CVE-2020-10119
< 84.0.20
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
9.8
CRITICAL
CVE-2020-10118
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
9.1
CRITICAL
CVE-2020-10117
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
9.1
CRITICAL
CVE-2020-10116
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-5
5.3
MEDIUM
CVE-2020-10115
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
7.2
HIGH
CVE-2020-10114
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
6.1
MEDIUM
CVE-2020-10113
>= 77.9999.110 and < 78.0.45
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
6.1
MEDIUM
CVE-2019-20498
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
9.8
CRITICAL
CVE-2019-20497
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
5.4
MEDIUM
CVE-2019-20496
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
5.5
MEDIUM
CVE-2019-20495
>= 81.9999.242 and < 82.0.18
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
6.5
MEDIUM
CVE-2019-20494
>= 77.9999.110 and < 78.0.43
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
3.3
LOW
CVE-2019-20493
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
6.1
MEDIUM
CVE-2019-20492
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
8.8
HIGH
CVE-2019-20490
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
8.8
HIGH
CVE-2019-20491
>= 77.9999.110 and < 78.0.43
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
5.4
MEDIUM
CVE-2012-6449
all versions
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
5.4
MEDIUM
CVE-2012-6448
all versions
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML
6.1
MEDIUM
CVE-2019-17380
< 82.0.15
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
6.1
MEDIUM
CVE-2019-17379
>= 77.9999.110 and < 78.0.39
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
6.1
MEDIUM
CVE-2019-17378
>= 77.9999.110 and < 78.0.39
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
6.1
MEDIUM
CVE-2019-17377
>= 77.9999.110 and < 78.0.39
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
6.1
MEDIUM
CVE-2019-17376
>= 77.9999.110 and < 78.0.39
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
6.1
MEDIUM
CVE-2019-17375
>= 81.9999.242 and < 82.0.15
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
8.8
HIGH
CVE-2016-10812
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
8.8
HIGH
CVE-2016-10811
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
8.8
HIGH
CVE-2016-10810
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
8.8
HIGH
CVE-2016-10809
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
8.8
HIGH
CVE-2016-10808
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
8.8
HIGH
CVE-2016-10807
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
6.5
MEDIUM
CVE-2016-10806
>= 11.54.0.0 and < 11.54.0.24
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
5.4
MEDIUM
CVE-2016-10805
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
8.8
HIGH
CVE-2016-10804
>= 11.50.0.4 and < 11.50.6.2
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
8.1
HIGH
CVE-2016-10803
>= 57.9999.48 and < 57.9999.105
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
7.5
HIGH
CVE-2016-10802
>= 11.51.9999.98 and < 11.52.6.2
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
8.8
HIGH
CVE-2016-10801
>= 11.54.0.0 and < 11.54.0.26
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
8.8
HIGH
CVE-2016-10800
>= 55.9999.61 and < 56.0.27
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
7.8
HIGH
CVE-2016-10799
>= 11.51.9999.98 and < 11.52.6.2
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
5.5
MEDIUM
CVE-2016-10798
>= 55.9999.61 and < 56.0.27
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
6.8
MEDIUM
CVE-2016-10797
>= 55.9999.61 and < 56.0.27
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
4.3
MEDIUM
CVE-2016-10796
>= 11.51.9999.98 and < 11.52.6.2
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
3.3
LOW
CVE-2016-10795
>= 11.51.9999.98 and < 11.52.6.6
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
6.1
MEDIUM
CVE-2016-10794
>= 11.51.9999.98 and < 11.52.6.6
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
6.5
MEDIUM
CVE-2016-10793
>= 11.51.9999.98 and < 11.52.6.6
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
8.8
HIGH
CVE-2016-10792
>= 11.51.9999.98 and < 11.52.6.6
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
8.8
HIGH
CVE-2016-10791
>= 59.9999.58 and < 60.0.15
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559).
5.3
MEDIUM
CVE-2016-10790
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
7.5
HIGH
CVE-2016-10789
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
8.8
HIGH
CVE-2016-10788
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
8.8
HIGH
CVE-2016-10787
>= 11.54.0.0 and < 11.54.0.33
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
8.1
HIGH
CVE-2016-10786
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
6.5
MEDIUM
CVE-2016-10785
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
6.5
MEDIUM
CVE-2016-10784
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
5.4
MEDIUM
CVE-2016-10783
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
5.4
MEDIUM
CVE-2016-10782
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
5.4
MEDIUM
CVE-2016-10781
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
5.4
MEDIUM
CVE-2016-10780
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
5.4
MEDIUM
CVE-2016-10779
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
5.4
MEDIUM
CVE-2016-10778
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
5.4
MEDIUM
CVE-2016-10777
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
5.4
MEDIUM
CVE-2016-10776
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
5.4
MEDIUM
CVE-2017-18482
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
6.5
MEDIUM
CVE-2017-18481
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
5.4
MEDIUM
CVE-2017-18480
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
6.5
MEDIUM
CVE-2017-18479
>= 11.54.0.0 and < 11.54.0.36
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
6.5
MEDIUM
CVE-2017-18478
>= 11.54.0.0 and < 11.54.0.36
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
6.5
MEDIUM
CVE-2017-18477
>= 11.54.0.0 and < 11.54.0.36
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
6.5
MEDIUM
CVE-2017-18476
>= 11.54.0.0 and < 11.54.0.36
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
7.5
HIGH
CVE-2017-18475
>= 11.54.0.0 and < 11.54.0.36
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-
8.8
HIGH
CVE-2017-18474
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
6.5
MEDIUM
CVE-2017-18473
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
5.4
MEDIUM
CVE-2017-18472
>= 55.9999.61 and < 56.0.43
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
6.1
MEDIUM
CVE-2017-18471
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
5.4
MEDIUM
CVE-2017-18470
>= 11.54.0.0 and < 11.54.0.36
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
8.8
HIGH
CVE-2017-18469
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
6.3
MEDIUM
CVE-2016-10775
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
6.5
MEDIUM
CVE-2016-10774
>= 59.9999.58 and < 60.0.25
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
5.4
MEDIUM
CVE-2016-10773
>= 59.9999.58 and < 60.0.25
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
8.8
HIGH
CVE-2016-10772
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).
3.3
LOW
CVE-2016-10771
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
8.1
HIGH
CVE-2016-10770
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
6.5
MEDIUM
CVE-2016-10769
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
6.1
MEDIUM
CVE-2016-10768
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
6.5
MEDIUM
CVE-2016-10767
>= 11.54.0.0 and < 11.54.0.33
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
5.4
MEDIUM
CVE-2017-18468
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
6.3
MEDIUM
CVE-2017-18467
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
4.3
MEDIUM
CVE-2017-18466
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-
2.7
LOW
CVE-2017-18465
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
4.4
MEDIUM
CVE-2017-18464
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
4.9
MEDIUM
CVE-2017-18462
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
7.5
HIGH
CVE-2017-18463
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
7.8
HIGH
CVE-2017-18461
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
4.3
MEDIUM
CVE-2017-18460
>= 59.9999.58 and < 60.0.39
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
7.8
HIGH
CVE-2017-18459
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
7.8
HIGH
CVE-2017-18458
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
3.3
LOW
CVE-2017-18457
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
4.4
MEDIUM
CVE-2017-18456
>= 55.9999.61 and < 56.0.46
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
6.1
MEDIUM
CVE-2017-18455
>= 55.9999.61 and < 56.0.46
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
2.7
LOW
CVE-2017-18454
>= 55.9999.61 and < 56.0.49
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
5.4
MEDIUM
CVE-2017-18453
>= 56.0.1 and < 56.0.49
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
4.9
MEDIUM
CVE-2017-18452
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
6.7
MEDIUM
CVE-2017-18451
>= 56.0.1 and < 56.0.49
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257)
5.3
MEDIUM
CVE-2017-18450
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
4.5
MEDIUM
CVE-2017-18449
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql
5.5
MEDIUM
CVE-2017-18448
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
5.3
MEDIUM
CVE-2017-18447
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
6.3
MEDIUM
CVE-2017-18446
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
6.3
MEDIUM
CVE-2017-18445
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
4.3
MEDIUM
CVE-2017-18444
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
5.3
MEDIUM
CVE-2017-18443
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
5.8
MEDIUM
CVE-2017-18442
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
5.3
MEDIUM
CVE-2017-18441
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
5.0
MEDIUM
CVE-2017-18440
>= 56.0.1 and < 56.0.49
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
4.3
MEDIUM
CVE-2017-18439
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
6.3
MEDIUM
CVE-2017-18438
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
6.3
MEDIUM
CVE-2017-18437
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
4.4
MEDIUM
CVE-2017-18436
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
3.5
LOW
CVE-2017-18435
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
7.3
HIGH
CVE-2017-18434
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin cal
7.8
HIGH
CVE-2017-18433
>= 55.9999.61 and < 56.0.49
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
8.8
HIGH
CVE-2017-18432
>= 55.9999.61 and < 56.0.49
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
7.8
HIGH
CVE-2017-18431
>= 65.9999.38 and < 66.0.1
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
7.5
HIGH
CVE-2017-18430
>= 55.9999.61 and < 56.0.51
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
4.7
MEDIUM
CVE-2017-18429
>= 55.9999.61 and < 56.0.51
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
3.3
LOW
CVE-2017-18428
>= 55.9999.61 and < 56.0.51
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
2.5
LOW
CVE-2017-18427
>= 55.9999.61 and < 56.0.51
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
3.3
LOW
CVE-2017-18426
< 66.0.2
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
2.7
LOW
CVE-2017-18425
>= 56.0.1 and < 56.0.51
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
2.5
LOW
CVE-2017-18424
>= 60.0.3 and < 60.0.45
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
3.3
LOW
CVE-2017-18423
>= 56.0.1 and < 56.0.51
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
3.3
LOW
CVE-2017-18422
>= 56.0.1 and < 56.0.51
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
3.3
LOW
CVE-2017-18421
>= 60.0.3 and < 60.0.45
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
3.3
LOW
CVE-2017-18420
< 66.0.2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
5.4
MEDIUM
CVE-2017-18419
< 66.0.2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
5.4
MEDIUM
CVE-2017-18418
< 66.0.2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
5.4
MEDIUM
CVE-2017-18417
< 66.0.2
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
5.4
MEDIUM
CVE-2017-18416
< 56.0.52
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
5.5
MEDIUM
CVE-2017-18415
< 56.0.52
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable fi
7.8
HIGH
CVE-2017-18414
< 56.0.52
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
7.4
HIGH
CVE-2017-18413
>= 55.9999.61 and < 56.0.52
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
7.8
HIGH
CVE-2017-18412
>= 55.9999.61 and < 56.0.52
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename
2.5
LOW
CVE-2017-18411
>= 55.9999.61 and < 56.0.52
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
6.8
MEDIUM
CVE-2017-18410
>= 55.9999.61 and < 56.0.52
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
6.5
MEDIUM
CVE-2017-18409
>= 55.9999.61 and < 56.0.52
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
6.5
MEDIUM
CVE-2017-18408
>= 55.9999.61 and < 56.0.52
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
5.4
MEDIUM
CVE-2017-18407
>= 59.9999.58 and < 60.0.48
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
4.8
MEDIUM
CVE-2017-18406
>= 63.9999.74 and < 64.0.40
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
7.5
HIGH
CVE-2017-18405
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
5.5
MEDIUM
CVE-2017-18404
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
3.1
LOW
CVE-2017-18403
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
6.3
MEDIUM
CVE-2017-18402
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
5.4
MEDIUM
CVE-2017-18401
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
2.7
LOW
CVE-2017-18400
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
7.8
HIGH
CVE-2017-18399
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqlopti
3.7
LOW
CVE-2017-18398
>= 61.9999.55 and < 62.0.35
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
3.8
LOW
CVE-2017-18397
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
3.3
LOW
CVE-2017-18396
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
5.5
MEDIUM
CVE-2017-18395
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
2.7
LOW
CVE-2017-18394
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
2.7
LOW
CVE-2017-18393
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
2.7
LOW
CVE-2017-18392
>= 63.9999.74 and < 64.0.42
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
2.0
LOW
CVE-2017-18391
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323)
2.5
LOW
CVE-2017-18390
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups
7.8
HIGH
CVE-2017-18389
>= 63.9999.74 and < 64.0.42
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
6.3
MEDIUM
CVE-2017-18388
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
7.8
HIGH
CVE-2017-18387
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
7.2
HIGH
CVE-2017-18386
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
7.2
HIGH
CVE-2017-18385
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
5.5
MEDIUM
CVE-2017-18384
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
3.8
LOW
CVE-2017-18383
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
7.8
HIGH
CVE-2017-18382
>= 61.9999.55 and < 62.0.35
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
2.7
LOW
CVE-2016-10826
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
8.8
HIGH
CVE-2016-10821
>= 11.50.0.4 and < 11.50.5.2
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
6.5
MEDIUM
CVE-2016-10820
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
8.8
HIGH
CVE-2016-10819
>= 11.50.0.4 and < 11.50.6.2
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
6.5
MEDIUM
CVE-2016-10818
< 56.0.15
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
6.5
MEDIUM
CVE-2016-10817
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
9.8
CRITICAL
CVE-2016-10816
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
8.8
HIGH
CVE-2016-10815
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
6.5
MEDIUM
CVE-2016-10814
>= 11.50.0.4 and < 11.50.6.2
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
8.8
HIGH
CVE-2016-10813
>= 11.54.0.1 and < 11.54.0.24
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
5.4
MEDIUM
CVE-2018-20953
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
6.1
MEDIUM
CVE-2018-20952
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
6.5
MEDIUM
CVE-2018-20951
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
6.1
MEDIUM
CVE-2018-20950
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
6.1
MEDIUM
CVE-2018-20949
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
6.1
MEDIUM
CVE-2018-20948
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
6.1
MEDIUM
CVE-2018-20947
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
5.5
MEDIUM
CVE-2018-20946
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zo
3.3
LOW
CVE-2018-20945
>= 61.9999.55 and < 62.0.39
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
5.7
MEDIUM
CVE-2018-20944
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
3.3
LOW
CVE-2018-20943
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
2.5
LOW
CVE-2018-20942
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351)
2.5
LOW
CVE-2018-20941
>= 67.9999.64 and < 68.0.27
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
5.6
MEDIUM
CVE-2018-20940
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-
3.3
LOW
CVE-2018-20939
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (S
3.3
LOW
CVE-2018-20938
>= 67.9999.64 and < 68.0.27
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
2.7
LOW
CVE-2018-20937
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
4.3
MEDIUM
CVE-2018-20936
>= 61.9999.55 and < 62.0.39
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
3.3
LOW
CVE-2016-10835
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
4.3
MEDIUM
CVE-2016-10834
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
8.8
HIGH
CVE-2016-10833
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
7.5
HIGH
CVE-2016-10832
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
6.5
MEDIUM
CVE-2016-10831
>= 11.54.0.0 and < 11.54.0.20
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
7.2
HIGH
CVE-2016-10830
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
8.1
HIGH
CVE-2016-10829
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
6.5
MEDIUM
CVE-2016-10828
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
8.8
HIGH
CVE-2016-10827
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
5.4
MEDIUM
CVE-2016-10825
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
8.1
HIGH
CVE-2016-10824
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
9.8
CRITICAL
CVE-2016-10823
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SE
8.8
HIGH
CVE-2016-10822
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
5.4
MEDIUM
CVE-2018-20935
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
5.4
MEDIUM
CVE-2018-20934
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
6.5
MEDIUM
CVE-2018-20933
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
5.4
MEDIUM
CVE-2018-20932
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
2.7
LOW
CVE-2018-20931
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
6.3
MEDIUM
CVE-2018-20930
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
6.5
MEDIUM
CVE-2018-20929
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
6.1
MEDIUM
CVE-2018-20928
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
6.1
MEDIUM
CVE-2018-20927
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
3.8
LOW
CVE-2018-20926
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
6.7
MEDIUM
CVE-2018-20925
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
6.7
MEDIUM
CVE-2018-20924
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
5.5
MEDIUM
CVE-2016-10849
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
6.5
MEDIUM
CVE-2016-10848
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
7.2
HIGH
CVE-2016-10847
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
8.1
HIGH
CVE-2016-10846
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
8.1
HIGH
CVE-2016-10845
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
8.1
HIGH
CVE-2016-10844
>= 11.48.0.5 and < 11.48.5.2
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
6.5
MEDIUM
CVE-2016-10843
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
8.1
HIGH
CVE-2016-10842
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
6.5
MEDIUM
CVE-2016-10841
>= 11.48.0.5 and < 11.48.5.2
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
5.3
MEDIUM
CVE-2016-10840
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
8.8
HIGH
CVE-2016-10839
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
8.1
HIGH
CVE-2016-10838
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
6.5
MEDIUM
CVE-2016-10837
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
7.5
HIGH
CVE-2016-10836
>= 11.50.0.4 and < 11.50.5.2
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
6.5
MEDIUM
CVE-2018-20923
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
6.1
MEDIUM
CVE-2018-20922
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
6.1
MEDIUM
CVE-2018-20921
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
6.1
MEDIUM
CVE-2018-20920
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
6.1
MEDIUM
CVE-2018-20919
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
6.1
MEDIUM
CVE-2018-20918
< 70.0.23
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
6.1
MEDIUM
CVE-2018-20917
< 70.0.23
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
5.5
MEDIUM
CVE-2018-20916
< 70.0.23
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
5.4
MEDIUM
CVE-2018-20915
< 70.0.23
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
5.4
MEDIUM
CVE-2018-20914
< 70.0.23
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
7.3
HIGH
CVE-2018-20913
< 70.0.23
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
4.9
MEDIUM
CVE-2018-20912
< 70.0.23
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
6.3
MEDIUM
CVE-2018-20911
< 70.0.23
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
7.2
HIGH
CVE-2018-20910
< 70.0.23
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
6.1
MEDIUM
CVE-2018-20909
>= 61.9999.55 and < 62.0.42
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
7.1
HIGH
CVE-2018-20908
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
5.5
MEDIUM
CVE-2018-20907
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
4.3
MEDIUM
CVE-2018-20906
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
4.3
MEDIUM
CVE-2018-20905
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
5.4
MEDIUM
CVE-2018-20904
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
4.3
MEDIUM
CVE-2018-20903
< 71.9980.37
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
6.1
MEDIUM
CVE-2018-20902
< 71.9980.37
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
5.5
MEDIUM
CVE-2018-20901
< 71.9980.37
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
6.1
MEDIUM
CVE-2016-10860
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
8.1
HIGH
CVE-2016-10859
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
8.1
HIGH
CVE-2016-10858
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
9.8
CRITICAL
CVE-2016-10857
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
6.5
MEDIUM
CVE-2016-10856
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
6.5
MEDIUM
CVE-2016-10855
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
9.8
CRITICAL
CVE-2016-10854
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
5.4
MEDIUM
CVE-2016-10853
>= 11.48.0.5 and < 11.48.4.8
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
5.4
MEDIUM
CVE-2016-10852
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
6.5
MEDIUM
CVE-2016-10851
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
5.4
MEDIUM
CVE-2016-10850
>= 11.48.0.5 and < 11.48.5.2
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
8.8
HIGH
CVE-2015-9291
< 11.52.0.13
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
7.5
HIGH
CVE-2018-20900
>= 62.0.1 and < 62.0.47
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
6.1
MEDIUM
CVE-2018-20899
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
6.1
MEDIUM
CVE-2018-20898
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
4.3
MEDIUM
CVE-2018-20897
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
2.8
LOW
CVE-2018-20896
>= 61.9999.55 and < 62.0.47
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
3.9
LOW
CVE-2018-20895
>= 67.9999.64 and < 68.0.39
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
7.2
HIGH
CVE-2018-20894
>= 71.9980.30 and < 72.0.10
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
3.3
LOW
CVE-2018-20893
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
2.3
LOW
CVE-2018-20892
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
4.3
MEDIUM
CVE-2018-20891
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
5.5
MEDIUM
CVE-2018-20890
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
4.3
MEDIUM
CVE-2018-20889
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
4.4
MEDIUM
CVE-2018-20888
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424
5.5
MEDIUM
CVE-2018-20887
< 74.0.0
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
9.8
CRITICAL
CVE-2018-20886
>= 69.9999.122 and < 70.0.53
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
5.3
MEDIUM
CVE-2018-20885
< 74.0.0
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
5.3
MEDIUM
CVE-2018-20884
< 74.0.0
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
5.4
MEDIUM
CVE-2018-20883
< 74.0.8
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
6.5
MEDIUM
CVE-2018-20882
>= 69.9999.122 and < 70.0.57
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (S
6.8
MEDIUM
CVE-2018-20881
< 74.0.8
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
5.4
MEDIUM
CVE-2018-20880
< 74.0.8
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
3.3
LOW
CVE-2018-20879
< 74.0.8
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
6.3
MEDIUM
CVE-2018-20878
< 74.0.8
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
5.4
MEDIUM
CVE-2018-20877
< 74.0.8
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
5.4
MEDIUM
CVE-2018-20876
< 74.0.8
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
5.4
MEDIUM
CVE-2018-20875
< 74.0.8
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
5.4
MEDIUM
CVE-2018-20874
>= 69.9999.122 and < 70.0.57
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
5.4
MEDIUM
CVE-2018-20873
>= 69.9999.122 and < 70.0.57
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
3.3
LOW
CVE-2019-14414
< 78.0.2
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
3.3
LOW
CVE-2019-14413
< 78.0.2
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
4.3
MEDIUM
CVE-2019-14412
< 78.0.2
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
3.3
LOW
CVE-2019-14411
< 78.0.2
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
5.3
MEDIUM
CVE-2019-14410
< 78.0.2
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
3.3
LOW
CVE-2019-14409
< 78.0.2
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
5.5
MEDIUM
CVE-2019-14408
< 78.0.2
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
4.3
MEDIUM
CVE-2019-14407
< 78.0.2
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
2.7
LOW
CVE-2019-14406
< 78.0.18
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
6.1
MEDIUM
CVE-2019-14405
< 78.0.18
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
8.8
HIGH
CVE-2019-14404
< 78.0.18
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router
5.5
MEDIUM
CVE-2019-14403
< 78.0.18
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
4.3
MEDIUM
CVE-2019-14402
< 78.0.18
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
3.3
LOW
CVE-2019-14401
< 78.0.18
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
8.8
HIGH
CVE-2019-14400
< 78.0.18
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
7.8
HIGH
CVE-2019-14399
< 78.0.18
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC
7.1
HIGH
CVE-2019-14398
< 80.0.5
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
8.8
HIGH
CVE-2019-14397
< 80.0.5
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
5.3
MEDIUM
CVE-2019-14396
< 80.0.5
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
3.3
LOW
CVE-2019-14395
< 80.0.5
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
3.3
LOW
CVE-2019-14394
< 80.0.5
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API
5.5
MEDIUM
CVE-2019-14393
< 80.0.5
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution
5.3
MEDIUM
CVE-2018-20870
< 76.0.8
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
5.5
MEDIUM
CVE-2018-20869
< 76.0.8
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
7.8
HIGH
CVE-2018-20868
< 76.0.8
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
6.1
MEDIUM
CVE-2018-20866
< 76.0.8
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
6.1
MEDIUM
CVE-2018-20865
< 76.0.8
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
6.1
MEDIUM
CVE-2018-20864
< 76.0.8
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
6.5
MEDIUM
CVE-2018-20863
< 76.0.8
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
9.8
CRITICAL
CVE-2018-20862
< 76.0.8
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
7.8
HIGH
CVE-2019-14392
< 80.0.22
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
8.8
HIGH
CVE-2018-20867
< 76.0.8
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
6.1
MEDIUM
CVE-2019-14391
< 82.0.2
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
3.3
LOW
CVE-2019-14390
< 82.0.2
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
5.4
MEDIUM
CVE-2019-14389
< 82.0.2
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
7.8
HIGH
CVE-2019-14388
< 82.0.2
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
7.5
HIGH
CVE-2019-14387
< 82.0.2
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
6.1
MEDIUM
CVE-2019-14386
< 82.0.2
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
5.4
MEDIUM
CVE-2018-16236
<= 74
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled
6.1
MEDIUM
CVE-2017-11441
<= 56.0.50
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x befo
5.4
MEDIUM
CVE-2017-5616
all versions
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML vi
6.1
MEDIUM
CVE-2017-5615
all versions
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
6.1
MEDIUM
CVE-2017-5614
>= 11.54.0.0 and < 11.54.0.36
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct p
6.1
MEDIUM
CVE-2017-5613
all versions
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers
7.8
HIGH
CVE-2009-4823
all versions
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers t
CVE-2008-7142
all versions
Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote a
CVE-2008-6927
all versions
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for c
CVE-2008-6843
all versions
Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary
CVE-2009-2275
all versions
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files vi
CVE-2008-2478
<= 11.23.1
scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with resell
CVE-2008-2071
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22
CVE-2008-2070
all versions
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protectio
CVE-2008-2043
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1)
CVE-2008-1499
all versions
Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to
CVE-2008-0370
all versions
Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject a
CVE-2007-4022
all versions
Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject
CVE-2007-3367
<= 10.9.0_build_10300
Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive
CVE-2007-3366
<= 10.9.0_build_10300
Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378,
CVE-2007-0890
all versions
Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote a
CVE-2007-0854
all versions
Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitr
CVE-2006-6548
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inje
CVE-2006-6523
all versions
Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrar
CVE-2006-6198
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inje
CVE-2006-5883
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script o
CVE-2006-5535
all versions
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inj
CVE-2006-5014
all versions
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vec
8.8
HIGH
CVE-2006-4293
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via
CVE-2006-3337
<= 10.8.2_current_118
Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote at
CVE-2006-2825
all versions
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts t
CVE-2006-0763
all versions
Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script
CVE-2006-0574
all versions
Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel 10 allows remote attackers to inject arbitrary web script o
CVE-2006-0573
all versions
Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script o
CVE-2006-0533
all versions
Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or H
CVE-2005-3505
all versions
Cross-site scripting (XSS) vulnerability in the Entropy Chat script in cPanel 10.2.0-R82 and 10.6.0-R137 allows remote attackers t
CVE-2005-2021
all versions
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML
CVE-2004-2308
all versions
Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web scri
CVE-2004-1603
all versions
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) cho
5.5
MEDIUM
CVE-2004-1604
all versions
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory,
CVE-2004-0490
all versions
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which c
CVE-2004-1875
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or H
CVE-2004-1849
all versions
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML
CVE-2004-1770
all versions
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metachar
CVE-2004-1769
all versions
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows rem
CVE-2003-1426
all versions
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC
CVE-2003-1425
all versions
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
CVE-2003-0521
all versions
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin