Show filters
425 Total Results
Displaying 1-10 of 425
Sort by:
Attacker Value
Moderate

CVE-2023-29489

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
Attacker Value
Unknown

CVE-2021-38589

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
Attacker Value
Unknown

CVE-2021-38590

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
Attacker Value
Unknown

CVE-2021-38585

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
Attacker Value
Unknown

CVE-2021-38586

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
Attacker Value
Unknown

CVE-2021-38584

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
Attacker Value
Unknown

CVE-2021-38588

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
Attacker Value
Unknown

CVE-2021-38587

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
Attacker Value
Unknown

CVE-2021-31803

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
Attacker Value
Unknown

CVE-2021-26266

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).