Show filters
421 Total Results
Displaying 1-10 of 421
Sort by:
Attacker Value
Moderate

CVE-2023-29489

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
Attacker Value
Unknown

CVE-2025-22690

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration allows Stored XSS. This issue affects DigiTimber cPanel Integration: from n/a through 1.4.6.
0
Attacker Value
Unknown

CVE-2024-34015

Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818.
0
Attacker Value
Unknown

CVE-2024-34014

Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.
0
Attacker Value
Unknown

CVE-2024-8767

Disclosure Date: September 17, 2024 (last updated September 17, 2024)
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
0
Attacker Value
Unknown

CVE-2022-48623

Disclosure Date: February 13, 2024 (last updated October 31, 2024)
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
Attacker Value
Unknown

CVE-2021-38589

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
Attacker Value
Unknown

CVE-2021-38590

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
Attacker Value
Unknown

CVE-2021-38585

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
Attacker Value
Unknown

CVE-2021-38586

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).