Search Results (40 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-29205 3 Cpanel, Webpros, Wordpress 6 Cpanel, Whm, Wp Squared and 3 more 2026-09-24 8.6 High
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
CVE-2026-29202 1 Webpros 3 Cpanel, Cpanel (centos 6, Cloudlinux 6), Wp Sqaured 2026-09-24 8.8 High
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
CVE-2026-68492 1 Webpros 2 Plesk, Plesk Extension "plesk Restful Api" 2026-09-24 N/A
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
CVE-2026-68490 1 Webpros 1 Cpanel 2026-09-24 N/A
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
CVE-2026-87900 1 Webpros 1 Wp Toolkit For Cpanel 2026-09-24 N/A
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
CVE-2026-87898 1 Webpros 1 Plesk Site Import 2026-09-24 N/A
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
CVE-2026-87899 1 Webpros 1 Cpanel 2026-09-23 N/A
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
CVE-2026-67398 1 Webpros 1 Whmcs 2026-09-21 N/A
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
CVE-2026-68491 1 Webpros 1 Solusvm 2026-09-18 N/A
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
CVE-2026-67399 1 Webpros 1 Whmcs 2026-09-17 N/A
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
CVE-2026-68489 1 Webpros 2 Plesk Extension "node.js Toolkit", Plesk Extension "ruby" 2026-09-17 8.8 High
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
CVE-2026-65646 1 Webpros 1 Plesk 2026-09-11 8.8 High
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
CVE-2026-68487 1 Webpros 1 Plesk 2026-09-11 N/A
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
CVE-2026-68488 1 Webpros 1 Plesk 2026-09-11 N/A
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
CVE-2026-67401 1 Webpros 1 Cpanel 2026-09-10 N/A
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
CVE-2026-65643 2 Cpanel, Webpros 2 Cpanel, Cpanel 2026-09-04 8.8 High
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
CVE-2026-67397 1 Webpros 1 Plesk 2026-09-04 N/A
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
CVE-2026-67394 1 Webpros 1 Plesk 2026-09-01 N/A
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
CVE-2026-65647 1 Webpros 2 Plesk Migrator, Plesk Site Import 2026-08-28 N/A
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
CVE-2026-65642 1 Webpros 1 Plesk 2026-08-27 8.1 High
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.