Cpanel
440 known vulnerabilities
Top Products
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incrementa
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of bac
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
Frequently Asked Questions
How many CVEs affect Cpanel?
Cpanel has 440 CVE records in our database, including 19 critical and 117 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Cpanel vulnerabilities?
Cpanel has 19 critical severity (CVSS 9.0+) and 117 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Cpanel vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Cpanel Vulnerabilities
CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.
Get Started