cpanel

426 tracked vulnerabilities.

CVE-2018-20865 MEDIUM
cPanel < 76.0.8 - Self Cross-Site Scripting in WHM Additional Backup Destination Field
Jul 30, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-20864 MEDIUM
cPanel < 76.0.8 - Persistent Virtual FTP Accounts After Domain Removal
Jul 30, 2019
CVSS 6.5
EPSS 0.00
CVE-2018-20863 CRITICAL
cPanel < 76.0.8 - Remote Code Execution via Mailing-List Attachments
Jul 30, 2019
CVSS 9.8
EPSS 0.03
CVE-2018-20862 HIGH
cPanel < 76.0.8 - Unauthenticated PostgreSQL Password Change
Jul 30, 2019
CVSS 7.8
EPSS 0.00
CVE-2018-20867 MEDIUM
cPanel < 76.0.8 - Open Redirect via Connection Reset
Jul 30, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-16236 MEDIUM
cPanel < 74 - Stored Cross-Site Scripting via Crafted Filename in Logs Subdirectory
Aug 30, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18482 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Authenticated Improper Input Validation in WHM enqueue_transfer_item API
Aug 05, 2019
CVSS 6.5
EPSS 0.01
CVE-2017-18481 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Stored Cross-Site Scripting in WHM Account Suspension List Interface
Aug 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18480 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Unauthenticated Account Ownership Bypass via WHM API has_mycnf_for_cpuser
Aug 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18479 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Improper Certificate Validation in WHM SSL Certificate Generation
Aug 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18478 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Exposure of Sensitive Information via Rearrange Account XML-API
Aug 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18477 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Unauthenticated Remote Code Execution via Exim Transport
Aug 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18476 HIGH
cPanel 11.54.0.0-11.54.0.35 - Unauthenticated Directory Access via Leech Protect Bypass
Aug 05, 2019
CVSS 7.5
EPSS 0.00
CVE-2017-18475 HIGH
cPanel 11.54.0.0-11.54.0.35 - Improper Input Validation in Exim Piped Filters
Aug 05, 2019
CVSS 8.8
EPSS 0.01
CVE-2017-18474 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Unauthenticated Arbitrary File Read via Exim Valiases
Aug 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2017-18473 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Stored Cross-Site Scripting in Webmail Password and Security Page
Aug 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18472 MEDIUM
cPanel 55.9999.61-61.9999.999 - Reflected Cross-Site Scripting in Reset-Password Interface
Aug 05, 2019
CVSS 6.1
EPSS 0.00
CVE-2017-18471 MEDIUM
cPanel 11.54.0.0-11.54.0.35 - Stored Cross-Site Scripting in Paper Lantern Password-Change Screen
Aug 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18470 HIGH
cPanel 11.54.0.0-11.54.0.35 - Unauthenticated Fixed Password Exposure in Munin MySQL Test Account
Aug 05, 2019
CVSS 8.8
EPSS 0.00
CVE-2017-18469 MEDIUM
cPanel < 56.0.46 - Authenticated Remote Code Execution via NVData_fetchinc API
Aug 05, 2019
CVSS 6.3
EPSS 0.01
CVE-2017-18468 MEDIUM
cPanel 55.9999.61-61.9999.999 - Authenticated Remote Code Execution via Htaccess::setphppreference API
Aug 05, 2019
CVSS 6.3
EPSS 0.01
CVE-2017-18467 MEDIUM
cPanel < 56.0.46 - Unauthenticated Access to Restricted Resources via URL Filtering Error
Aug 05, 2019
CVSS 4.3
EPSS 0.00
CVE-2017-18466 LOW
cPanel 55.9999.61-62.0.16 - Improper Input Validation in Parked Domain Mail Configuration
Aug 05, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18465 MEDIUM
cPanel 55.9999.61-62.0.16 - Improper Input Validation
Aug 05, 2019
CVSS 4.4
EPSS 0.00
CVE-2017-18464 MEDIUM
cPanel < 56.0.46 - Arbitrary File Overwrite via WHM Zone Template Editor
Aug 05, 2019
CVSS 4.9
EPSS 0.00