← Back

Whm

whm

Vendor: Cpanel • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
3Cpanel
WhmWp Squared
Jun 17, 2026
Apr 29, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
1Cpanel
2Cpanel
Whm
Nov 21, 2024
Feb 10, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
1Cpanel
1Whm
May 13, 2026
Jul 19, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.