Vulnerabilities > Cpanel > Cpanel > 11.54.0.21
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-01 | CVE-2016-10818 | Permission Issues vulnerability in Cpanel cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124). | 4.0 |
2019-08-01 | CVE-2016-10817 | SQL Injection vulnerability in Cpanel cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123). | 10.0 |
2019-08-01 | CVE-2016-10816 | Improper Input Validation vulnerability in Cpanel cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121). | 6.5 |
2019-08-01 | CVE-2016-10815 | Information Exposure vulnerability in Cpanel cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120). | 4.0 |
2019-08-01 | CVE-2016-10814 | Improper Input Validation vulnerability in Cpanel cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119). | 6.5 |
2019-08-01 | CVE-2016-10813 | Cross-site Scripting vulnerability in Cpanel cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118). | 3.5 |
2019-08-01 | CVE-2018-20923 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | 4.3 |
2019-08-01 | CVE-2018-20922 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | 4.3 |
2019-08-01 | CVE-2018-20921 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | 4.3 |
2019-08-01 | CVE-2018-20920 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | 4.3 |