Home/Product/ispconfig
Product

ispconfig

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-52206
all versions
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
4.7MEDIUM
CVE-2023-46818
< 3.2.11
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin i
7.2HIGH
CVE-2021-3021
< 3.2.2
ISPConfig before 3.2.2 allows SQL injection.
9.8CRITICAL
CVE-2020-9398
< 3.1.15
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injectio
9.8CRITICAL
CVE-2013-3629
all versions
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
8.8HIGH
CVE-2012-2087
all versions
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
9.8CRITICAL
CVE-2018-17984
< 3.1.13
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to co
7.8HIGH
CVE-2017-17384
all versions
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
8.8HIGH
CVE-2015-4119
<= 3.0.5.4
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the auth
CVE-2015-4118
<= 3.0.5.4
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with mon
CVE-2006-3042
all versions
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a U
CVE-2006-2315
<= 2.2.2
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbit
threatengine.sh