Vulnerabilities > Cpanel

DATE CVE VULNERABILITY TITLE RISK
2023-04-27 CVE-2023-29489 Cross-site Scripting vulnerability in Cpanel
An issue was discovered in cPanel before 11.109.9999.116.
network
low complexity
cpanel CWE-79
6.1
2021-08-11 CVE-2021-38584 XXE vulnerability in Cpanel
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
network
low complexity
cpanel CWE-611
7.2
2021-08-11 CVE-2021-38585 Deserialization of Untrusted Data vulnerability in Cpanel
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
network
low complexity
cpanel CWE-502
7.2
2021-08-11 CVE-2021-38586 Unspecified vulnerability in Cpanel
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
local
low complexity
cpanel
4.4
2021-08-11 CVE-2021-38587 Race Condition vulnerability in Cpanel
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
network
low complexity
cpanel CWE-362
7.5
2021-08-11 CVE-2021-38588 Download of Code Without Integrity Check vulnerability in Cpanel
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
network
high complexity
cpanel CWE-494
8.1
2021-08-11 CVE-2021-38589 Unspecified vulnerability in Cpanel
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
network
low complexity
cpanel
8.1
2021-08-11 CVE-2021-38590 Incorrect Permission Assignment for Critical Resource vulnerability in Cpanel
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
local
low complexity
cpanel CWE-732
5.5
2021-04-26 CVE-2021-31803 Cross-site Scripting vulnerability in Cpanel
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
network
low complexity
cpanel CWE-79
6.1
2021-01-26 CVE-2021-26267 Unspecified vulnerability in Cpanel
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
network
low complexity
cpanel
7.5