Vulnerabilities > Cpanel > Cpanel > 11.42.1.29

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2018-20922 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
network
cpanel CWE-79
4.3
2019-08-01 CVE-2018-20921 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
network
cpanel CWE-79
4.3
2019-08-01 CVE-2018-20920 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
network
cpanel CWE-79
4.3
2019-08-01 CVE-2018-20919 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
network
cpanel CWE-79
4.3
2019-08-01 CVE-2018-20918 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
network
cpanel CWE-79
4.3
2019-08-01 CVE-2018-20917 Improper Input Validation vulnerability in Cpanel
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
local
low complexity
cpanel CWE-20
2.1
2019-08-01 CVE-2018-20916 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2018-20915 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2018-20914 Injection vulnerability in Cpanel
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
network
cpanel CWE-74
4.9
2019-08-01 CVE-2018-20913 Information Exposure vulnerability in Cpanel
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
network
cpanel CWE-200
3.5