Vulnerabilities (CVE)

Filtered by vendor Cpanel Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14403 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 4.3 MEDIUM
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
CVE-2018-20866 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
CVE-2018-20868 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2019-14406 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
CVE-2018-20865 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
CVE-2019-14387 1 Cpanel 1 Cpanel 2019-07-30 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
CVE-2019-14386 1 Cpanel 1 Cpanel 2019-07-30 3.5 LOW 5.4 MEDIUM
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
CVE-2019-14390 1 Cpanel 1 Cpanel 2019-07-30 3.5 LOW 5.4 MEDIUM
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
CVE-2018-16236 1 Cpanel 1 Cpanel 2018-10-23 4.3 MEDIUM 6.1 MEDIUM
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
CVE-2017-11441 1 Cpanel 1 Whm 2017-08-15 3.5 LOW 5.4 MEDIUM
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
CVE-2017-5615 1 Cpanel 2 Cgiecho, Cgiemail 2017-03-07 5.8 MEDIUM 6.1 MEDIUM
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
CVE-2017-5616 1 Cpanel 2 Cgiecho, Cgiemail 2017-03-07 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.