Show filters
421 Total Results
Displaying 1-10 of 421
Sort by:
Attacker Value
Moderate
CVE-2023-29489
Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
2
Attacker Value
Unknown
CVE-2025-22690
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration allows Stored XSS. This issue affects DigiTimber cPanel Integration: from n/a through 1.4.6.
0
Attacker Value
Unknown
CVE-2024-34015
Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818.
0
Attacker Value
Unknown
CVE-2024-34014
Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.
0
Attacker Value
Unknown
CVE-2024-8767
Disclosure Date: September 17, 2024 (last updated September 17, 2024)
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
0
Attacker Value
Unknown
CVE-2022-48623
Disclosure Date: February 13, 2024 (last updated October 31, 2024)
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
0
Attacker Value
Unknown
CVE-2021-38589
Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
0
Attacker Value
Unknown
CVE-2021-38590
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
0
Attacker Value
Unknown
CVE-2021-38585
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
0
Attacker Value
Unknown
CVE-2021-38586
Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
0