Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
Filtered by product Cpanel
Total 417 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20883 1 Cpanel 1 Cpanel 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
CVE-2018-20918 1 Cpanel 1 Cpanel 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
CVE-2017-18424 1 Cpanel 1 Cpanel 2024-02-28 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
CVE-2018-20893 1 Cpanel 1 Cpanel 2024-02-28 2.1 LOW 2.3 LOW
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
CVE-2017-18422 1 Cpanel 1 Cpanel 2024-02-28 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
CVE-2017-18452 1 Cpanel 1 Cpanel 2024-02-28 4.6 MEDIUM 6.7 MEDIUM
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
CVE-2016-10811 1 Cpanel 1 Cpanel 2024-02-28 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
CVE-2016-10814 1 Cpanel 1 Cpanel 2024-02-28 6.5 MEDIUM 8.8 HIGH
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
CVE-2016-10781 1 Cpanel 1 Cpanel 2024-02-28 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
CVE-2016-10776 1 Cpanel 1 Cpanel 2024-02-28 3.5 LOW 5.4 MEDIUM
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
CVE-2016-10794 1 Cpanel 1 Cpanel 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
CVE-2016-10792 1 Cpanel 1 Cpanel 2024-02-28 6.5 MEDIUM 8.8 HIGH
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
CVE-2017-18383 1 Cpanel 1 Cpanel 2024-02-28 4.6 MEDIUM 7.8 HIGH
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
CVE-2017-18394 1 Cpanel 1 Cpanel 2024-02-28 4.0 MEDIUM 2.7 LOW
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
CVE-2017-18435 1 Cpanel 1 Cpanel 2024-02-28 7.5 HIGH 7.3 HIGH
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2018-20888 1 Cpanel 1 Cpanel 2024-02-28 4.9 MEDIUM 5.5 MEDIUM
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
CVE-2019-14393 1 Cpanel 1 Cpanel 2024-02-28 4.6 MEDIUM 5.3 MEDIUM
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
CVE-2017-18415 1 Cpanel 1 Cpanel 2024-02-28 4.6 MEDIUM 7.8 HIGH
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
CVE-2016-10833 1 Cpanel 1 Cpanel 2024-02-28 5.0 MEDIUM 7.5 HIGH
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
CVE-2018-20897 1 Cpanel 1 Cpanel 2024-02-28 3.3 LOW 2.8 LOW
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).