Skip to main content

Vendor archive

cpanel CVEs

Beta · best-effort

428 CVEs tagged to vendor cpanel21 Critical, 106 High, 244 Medium, 57 Low, 0 Unrated.

CVE-2018-20887

Published Aug 1, 2019

cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20886

Published Aug 1, 2019

cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20885

Published Aug 1, 2019

cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20884

Published Aug 1, 2019

cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20883

Published Aug 1, 2019

cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20882

Published Aug 1, 2019

cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20881

Published Aug 1, 2019

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20880

Published Aug 1, 2019

cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20879

Published Aug 1, 2019

cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20878

Published Aug 1, 2019

cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20877

Published Aug 1, 2019

cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20876

Published Aug 1, 2019

cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20875

Published Aug 1, 2019

cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20874

Published Aug 1, 2019

cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20873

Published Aug 1, 2019

cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14414

Published Jul 30, 2019

In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14413

Published Jul 30, 2019

cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14412

Published Jul 30, 2019

Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14411

Published Jul 30, 2019

cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14410

Published Jul 30, 2019

Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14409

Published Jul 30, 2019

cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14408

Published Jul 30, 2019

cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14407

Published Jul 30, 2019

cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14406

Published Jul 30, 2019

cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14405

Published Jul 30, 2019

cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 428 CVEsPage 14 of 18