Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cpanel

440 known vulnerabilities

17
CRITICAL
103
HIGH
213
MEDIUM
53
LOW

Top Products

cpanel 381 whm 5 wp squared 3 cgiecho 3 cgiemail 3 webhost manager 1
386 CVEs · Page 7/8
5.5
CVE-2018-20902

cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).

6.1
CVE-2018-20901

cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).

8.1
CVE-2016-10860

cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).

8.1
CVE-2016-10859

cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

9.8
CVE-2016-10858

cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

6.5
CVE-2016-10857

cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

6.5
CVE-2016-10856

cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

9.8
CVE-2016-10855

cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

5.4
CVE-2016-10854

cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).

5.4
CVE-2016-10853

cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).

6.5
CVE-2016-10852

cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

5.4
CVE-2016-10851

cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

8.8
CVE-2016-10850

cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

7.5
CVE-2015-9291

cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-12

6.1
CVE-2018-20900

cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).

6.1
CVE-2018-20899

cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).

4.3
CVE-2018-20898

cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

2.8
CVE-2018-20897

cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).

3.9
CVE-2018-20896

cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).

7.2
CVE-2018-20895

In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-39

3.3
CVE-2018-20894

cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).

2.3
CVE-2018-20893

cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).

4.3
CVE-2018-20892

cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).

5.5
CVE-2018-20891

cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

4.3
CVE-2018-20890

cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).

4.4
CVE-2018-20889

cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).

5.5
CVE-2018-20888

cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authenticatio

9.8
CVE-2018-20887

cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

5.3
CVE-2018-20886

cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).

5.3
CVE-2018-20885

cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (S

5.4
CVE-2018-20884

cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).

6.5
CVE-2018-20883

cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

6.8
CVE-2018-20882

cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password

5.4
CVE-2018-20881

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

3.3
CVE-2018-20880

cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).

6.3
CVE-2018-20879

cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

5.4
CVE-2018-20878

cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).

5.4
CVE-2018-20877

cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).

5.4
CVE-2018-20876

cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).

5.4
CVE-2018-20875

cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).

5.4
CVE-2018-20874

cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).

3.3
CVE-2018-20873

cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).

3.3
CVE-2019-14414

In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).

4.3
CVE-2019-14413

cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

3.3
CVE-2019-14412

Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

5.3
CVE-2019-14411

cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).

3.3
CVE-2019-14410

Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

5.5
CVE-2019-14409

cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).

4.3
CVE-2019-14408

cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

2.7
CVE-2019-14407

cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

Frequently Asked Questions

How many CVEs affect Cpanel?

Cpanel has 440 CVE records in our database, including 19 critical and 117 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cpanel vulnerabilities?

Cpanel has 19 critical severity (CVSS 9.0+) and 117 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cpanel vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cpanel Vulnerabilities

CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.

Get Started