Cpanel
383 known vulnerabilities
Top Products
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang ad
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-2
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-v
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an acco
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345)
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabli
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incrementa
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
Frequently Asked Questions
How many CVEs affect Cpanel?
Cpanel has 383 CVE records in our database, including 9 critical and 88 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Cpanel vulnerabilities?
Cpanel has 9 critical severity (CVSS 9.0+) and 88 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Cpanel vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Cpanel Vulnerabilities
CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.
Get Started