← Back

Cpanel

cpanel

426 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Cpanel
cpanel
Cgiecho
cgiecho
Cgiemail
cgiemail
Whm
whm
Wp Squared
wp_squared

CVEs (426)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
1Cpanel
1Cpanel
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
1Cpanel
2Cpanel
Whm
Nov 21, 2024
Feb 10, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
1Cpanel
1Webhost Manager
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).