Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cpanel

440 known vulnerabilities

17
CRITICAL
103
HIGH
213
MEDIUM
53
LOW

Top Products

cpanel 381 whm 5 wp squared 3 cgiecho 3 cgiemail 3 webhost manager 1
386 CVEs · Page 5/8
2.7
CVE-2017-18393

cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).

2.0
CVE-2017-18392

cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).

2.5
CVE-2017-18391

cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval

7.8
CVE-2017-18390

cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incrementa

6.3
CVE-2017-18389

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

7.8
CVE-2017-18388

cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).

7.2
CVE-2017-18387

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

7.2
CVE-2017-18386

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

5.5
CVE-2017-18385

cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).

3.8
CVE-2017-18384

cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).

7.8
CVE-2017-18383

cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).

2.7
CVE-2017-18382

cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).

8.8
CVE-2016-10826

cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

6.5
CVE-2016-10821

In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).

8.8
CVE-2016-10820

cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

6.5
CVE-2016-10819

In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).

6.5
CVE-2016-10818

cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).

9.8
CVE-2016-10817

cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

8.8
CVE-2016-10816

cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).

6.5
CVE-2016-10815

cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).

8.8
CVE-2016-10814

cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

5.4
CVE-2016-10813

cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

6.1
CVE-2018-20953

cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).

6.5
CVE-2018-20952

cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).

6.1
CVE-2018-20951

cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).

6.1
CVE-2018-20950

cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).

6.1
CVE-2018-20949

cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).

6.1
CVE-2018-20948

cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).

5.5
CVE-2018-20947

cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).

3.3
CVE-2018-20946

cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi

5.7
CVE-2018-20945

bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).

3.3
CVE-2018-20944

cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).

2.5
CVE-2018-20943

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task

2.5
CVE-2018-20942

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab

5.6
CVE-2018-20941

cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).

3.3
CVE-2018-20940

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of bac

3.3
CVE-2018-20939

cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging

2.7
CVE-2018-20938

cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

4.3
CVE-2018-20937

cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).

3.3
CVE-2018-20936

cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

4.3
CVE-2016-10835

cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).

8.8
CVE-2016-10834

cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

7.5
CVE-2016-10833

cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

6.5
CVE-2016-10832

cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).

7.2
CVE-2016-10831

cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).

8.1
CVE-2016-10830

cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).

6.5
CVE-2016-10829

cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

8.8
CVE-2016-10828

cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).

5.4
CVE-2016-10827

cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).

8.1
CVE-2016-10825

cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

Frequently Asked Questions

How many CVEs affect Cpanel?

Cpanel has 440 CVE records in our database, including 19 critical and 117 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cpanel vulnerabilities?

Cpanel has 19 critical severity (CVSS 9.0+) and 117 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cpanel vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cpanel Vulnerabilities

CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.

Get Started