← Back

Cpanel

cpanel

426 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Cpanel
cpanel
Cgiecho
cgiecho
Cgiemail
cgiemail
Whm
whm
Wp Squared
wp_squared

CVEs (426)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
1Cpanel
1Cpanel
Jun 17, 2026
May 11, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
1Cpanel
1Cpanel
Jun 17, 2026
May 11, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).