← Back

Cpanel

cpanel

Vendor: Cpanel • 417 CVEs

CVEs (417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
1Cpanel
1Cpanel
May 13, 2026
Mar 3, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
1Cpanel
1Cpanel
Apr 29, 2026
Apr 27, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.