Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cpanel

383 known vulnerabilities

7
CRITICAL
82
HIGH
189
MEDIUM
52
LOW

Top Products

cpanel 326 whm 4 wp squared 3 cgiecho 3 cgiemail 3
330 CVEs · Page 3/7
4.4
CVE-2017-18437

cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).

3.5
CVE-2017-18436

cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).

7.3
CVE-2017-18435

cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

7.8
CVE-2017-18434

cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang ad

8.8
CVE-2017-18433

cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).

7.8
CVE-2017-18432

In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).

7.5
CVE-2017-18431

cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

4.7
CVE-2017-18430

In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-2

3.3
CVE-2017-18429

In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).

2.5
CVE-2017-18428

In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).

3.3
CVE-2017-18427

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

2.7
CVE-2017-18426

cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

2.5
CVE-2017-18425

In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

3.3
CVE-2017-18424

In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).

3.3
CVE-2017-18423

In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

3.3
CVE-2017-18422

In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).

3.3
CVE-2017-18421

cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).

5.4
CVE-2017-18420

cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).

5.4
CVE-2017-18419

cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).

5.4
CVE-2017-18418

cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

5.4
CVE-2017-18417

cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

5.5
CVE-2017-18416

cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).

7.8
CVE-2017-18415

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-v

7.4
CVE-2017-18414

cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

7.8
CVE-2017-18413

In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).

2.5
CVE-2017-18412

cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an acco

6.8
CVE-2017-18411

The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-

6.5
CVE-2017-18410

In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).

6.5
CVE-2017-18409

In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).

5.4
CVE-2017-18408

cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).

4.8
CVE-2017-18407

cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).

7.5
CVE-2017-18406

cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

5.5
CVE-2017-18405

cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345)

3.1
CVE-2017-18404

cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).

6.3
CVE-2017-18403

cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

5.4
CVE-2017-18402

cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).

2.7
CVE-2017-18401

cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).

7.8
CVE-2017-18400

cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).

3.7
CVE-2017-18399

cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabli

3.8
CVE-2017-18398

DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).

3.3
CVE-2017-18397

cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).

5.5
CVE-2017-18396

cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).

2.7
CVE-2017-18395

cPanel before 68.0.15 does not block a username of ssl (SEC-328).

2.7
CVE-2017-18394

cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).

2.7
CVE-2017-18393

cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).

2.0
CVE-2017-18392

cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).

2.5
CVE-2017-18391

cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval

7.8
CVE-2017-18390

cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incrementa

6.3
CVE-2017-18389

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

7.8
CVE-2017-18388

cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).

Frequently Asked Questions

How many CVEs affect Cpanel?

Cpanel has 383 CVE records in our database, including 9 critical and 88 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cpanel vulnerabilities?

Cpanel has 9 critical severity (CVSS 9.0+) and 88 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cpanel vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cpanel Vulnerabilities

CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.

Get Started