Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cpanel

440 known vulnerabilities

17
CRITICAL
103
HIGH
213
MEDIUM
53
LOW

Top Products

cpanel 381 whm 5 wp squared 3 cgiecho 3 cgiemail 3 webhost manager 1
386 CVEs · Page 8/8
6.1
CVE-2019-14406

cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).

8.8
CVE-2019-14405

cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

5.5
CVE-2019-14404

cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_s

4.3
CVE-2019-14403

cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

3.3
CVE-2019-14402

cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).

8.8
CVE-2019-14401

cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).

7.8
CVE-2019-14400

cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).

7.1
CVE-2019-14399

The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root ac

8.8
CVE-2019-14398

cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).

5.3
CVE-2019-14397

cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).

3.3
CVE-2019-14396

API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).

3.3
CVE-2019-14395

cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

5.5
CVE-2019-14394

cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for

5.3
CVE-2019-14393

cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp

5.5
CVE-2018-20870

The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

7.8
CVE-2018-20869

cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).

6.1
CVE-2018-20868

cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).

6.1
CVE-2018-20866

cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).

6.1
CVE-2018-20865

cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).

6.5
CVE-2018-20864

cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

9.8
CVE-2018-20863

cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

7.8
CVE-2018-20862

cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).

8.8
CVE-2019-14392

cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).

6.1
CVE-2018-20867

cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

3.3
CVE-2019-14391

cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).

5.4
CVE-2019-14390

cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).

7.8
CVE-2019-14389

cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).

7.5
CVE-2019-14388

cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).

6.1
CVE-2019-14387

cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).

5.4
CVE-2019-14386

cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).

6.1
CVE-2018-16236

cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is

5.4
CVE-2017-11441

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27,

6.1
CVE-2017-5616

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script

6.1
CVE-2017-5615

cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.

6.1
CVE-2017-5614

Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and

7.8
CVE-2017-5613

Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string

Frequently Asked Questions

How many CVEs affect Cpanel?

Cpanel has 440 CVE records in our database, including 19 critical and 117 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cpanel vulnerabilities?

Cpanel has 19 critical severity (CVSS 9.0+) and 117 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cpanel vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cpanel Vulnerabilities

CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.

Get Started