cpanel
426 tracked vulnerabilities.
CVE-2017-18388
HIGH
cPanel 61.9999.55-61.9999.9999 - Unsafe File Operations via Jailshell Umask Misconfiguration
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18387
HIGH
cPanel 61.9999.55-62.0.35 - Remote Code Execution via Maketext Injection in Reseller Style Upload
Aug 02, 2019
CVSS 7.2
EPSS 0.02
CVE-2017-18386
HIGH
cPanel 61.9999.55-61.9999.9999 - Remote Code Execution via Maketext Injection in PostgresAdmin
Aug 02, 2019
CVSS 7.2
EPSS 0.02
CVE-2017-18385
MEDIUM
cPanel 61.9999.55-62.0.35 - Unauthenticated Improper Access Control during Account Restore
Aug 02, 2019
CVSS 5.5
EPSS 0.00
CVE-2017-18384
LOW
cPanel 61.9999.55-61.9999.9999 - Improper Access Control via Jailed Account File Restore
Aug 02, 2019
CVSS 3.8
EPSS 0.00
CVE-2017-18383
HIGH
cPanel 61.9999.55-61.9999.9999 - Unauthenticated Path Traversal and Arbitrary File Write via Home-Directory Backup
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18382
LOW
cPanel 61.9999.55-62.0.35 - Improper Input Validation in DNS Zone SOA Records
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-11441
MEDIUM
cPanel WHM < 56.0.51 - Stored Cross-Site Scripting via Locale Filename Upload
Jul 19, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-5616
MEDIUM
cPanel cgiemail and cgiecho - Cross-Site Scripting via Addendum Parameter
Mar 03, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-5615
MEDIUM
cPanel cgiemail and cgiecho - HTTP Header Injection via Newline in Redirect Location
Mar 03, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-5614
MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Open Redirect via cgiemail/cgiecho Success/Failure Parameter
Mar 03, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-5613
HIGH
cPanel cgiecho and cgiemail - Remote Code Execution via Format String Specifiers in Template File
Mar 03, 2017
CVSS 7.8
EPSS 0.01
CVE-2016-10812
HIGH
cPanel 11.50.0.4-11.50.6.2 - Unauthenticated TTY Exposure via enablefileprotect Script
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10811
HIGH
cPanel 11.50.0.4-11.50.6.2 - Exposure of Sensitive Information via /scripts/unsuspendacct
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10810
HIGH
cPanel 11.50.0.4-11.50.6.2 - Exposure of Sensitive Information via TTY in maildir_converter
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10809
HIGH
cPanel 11.50.0.4-11.50.6.2 - Exposure of Sensitive Information via /scripts/checkinfopages
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10808
HIGH
cPanel 11.50.0.4-11.50.6.2 - Improper Input Validation in /scripts/addpop and /scripts/delpop
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10807
MEDIUM
cPanel 11.50.0.4-11.50.6.2 - Denial of Service via /scripts/killpvhost
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2016-10806
MEDIUM
cPanel 11.54.0.0-11.54.0.24 - Stored Cross-Site Scripting on Paper Lantern Landing Page
Aug 07, 2019
CVSS 5.4
EPSS 0.00
CVE-2016-10805
HIGH
cPanel 11.50.0.4-11.50.6.2 - Authenticated Remote Code Execution via ajax_maketext_syntax_util.pl
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10804
HIGH
cPanel 11.50.0.4-11.50.6.2 - Arbitrary File Overwrite via SQLite Journal Feature
Aug 07, 2019
CVSS 8.1
EPSS 0.00
CVE-2016-10803
HIGH
cPanel <57.9999.105 - Info Disclosure
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2016-10802
HIGH
cPanel 11.51.9999.98-11.52.6.2 - Remote Code Execution via PHP CGI Handler
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10801
HIGH
cPanel 11.54.0.0-11.54.0.25 - Improper Session Handling for Shared Users
Aug 07, 2019
CVSS 8.8
EPSS 0.01
CVE-2016-10800
HIGH
cPanel 55.9999.61-56.0.27 - Unauthenticated Demo-Mode Escape via Site Templates and Boxtrapper API
Aug 07, 2019
CVSS 7.8
EPSS 0.00
Products
Quick Filters