Cpanel
440 known vulnerabilities
Top Products
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_s
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root ac
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27,
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string
Frequently Asked Questions
How many CVEs affect Cpanel?
Cpanel has 440 CVE records in our database, including 19 critical and 117 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Cpanel vulnerabilities?
Cpanel has 19 critical severity (CVSS 9.0+) and 117 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Cpanel vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cpanel products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Cpanel Vulnerabilities
CyberStrike scans your infrastructure for Cpanel vulnerabilities and provides real-time remediation guidance.
Get Started