Product
ispconfig
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-52206
CVE-2023-46818
CVE-2021-3021
CVE-2020-9398
CVE-2013-3629
CVE-2012-2087
CVE-2018-17984
CVE-2017-17384
CVE-2015-4119
CVE-2015-4118
CVE-2006-3042
CVE-2006-2315
all versions
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
< 3.2.11
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin i
< 3.2.2
ISPConfig before 3.2.2 allows SQL injection.
< 3.1.15
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injectio
all versions
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
all versions
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
< 3.1.13
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to co
all versions
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
<= 3.0.5.4
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the auth
<= 3.0.5.4
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with mon
all versions
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a U
<= 2.2.2
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbit