Search
Find a vulnerability
Search criteria
46 vulnerabilities by WebPros
CVE-2026-93029 (GCVE-0-2026-93029)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:12
VLAI
EPSS
VEX
Summary
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Severity
9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 18:12 UTC
CWE
- CWE-79 - Cross-site Scripting (XSS) - Stored
Assigner
References
7 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Webpros | cPanel |
Affected:
0 , < 11.138.0.11
(semver)
Affected: 0 , < 11.136.0.45 (semver) Affected: 0 , < 11.134.0.61 (semver) Affected: 0 , < 11.110.0.148 (semver) |
|
| Webpros | WP Squared |
Affected:
0 , < 11.138.1.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93029",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T18:12:23.705554Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T18:12:44.517Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.0.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.45",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.61",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.110.0.148",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WP Squared",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.1.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "rz1027 (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Cross-site Scripting (XSS) - Stored",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:20:47.333Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://hackerone.com/reports/4047106"
},
{
"url": "https://support.cpanel.net/hc/en-us/articles/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026"
},
{
"url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
},
{
"url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
},
{
"url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
},
{
"url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
},
{
"url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-93029",
"datePublished": "2026-10-02T06:20:47.333Z",
"dateReserved": "2026-09-17T15:00:00.689Z",
"dateUpdated": "2026-10-02T18:12:44.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93697 (GCVE-0-2026-93697)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:14
VLAI
EPSS
VEX
Summary
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Severity
9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 18:12 UTC
CWE
- CWE-79 - Cross-site Scripting (XSS) - Stored
Assigner
References
7 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Webpros | cPanel |
Affected:
0 , < 11.138.0.11
(semver)
Affected: 0 , < 11.136.0.45 (semver) Affected: 0 , < 11.134.0.61 (semver) Affected: 0 , < 11.110.0.148 (semver) |
|
| Webpros | WP Squared |
Affected:
0 , < 11.138.1.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93697",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T18:12:58.690897Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T18:14:02.299Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.0.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.45",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.61",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.110.0.148",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WP Squared",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.1.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "rz1027 (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Cross-site Scripting (XSS) - Stored",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:20:44.084Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://hackerone.com/reports/4047787"
},
{
"url": "https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026"
},
{
"url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
},
{
"url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
},
{
"url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
},
{
"url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
},
{
"url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-93697",
"datePublished": "2026-10-02T06:20:44.084Z",
"dateReserved": "2026-09-18T15:00:00.594Z",
"dateUpdated": "2026-10-02T18:14:02.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93698 (GCVE-0-2026-93698)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:14
VLAI
EPSS
VEX
Summary
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 18:14 UTC
CWE
- CWE-78 - OS Command Injection
Assigner
References
7 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Webpros | cPanel |
Affected:
0 , < 11.138.0.11
(semver)
Affected: 0 , < 11.136.0.45 (semver) Affected: 0 , < 11.134.0.61 (semver) Affected: 0 , < 11.110.0.148 (semver) |
|
| Webpros | WP Squared |
Affected:
0 , < 11.138.1.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93698",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T18:14:35.329248Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T18:14:48.415Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.0.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.45",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.61",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.110.0.148",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WP Squared",
"vendor": "Webpros",
"versions": [
{
"lessThan": "11.138.1.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "rz1027 (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:20:33.663Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://hackerone.com/reports/4054291"
},
{
"url": "https://support.cpanel.net/hc/en-us/articles/43845931719447-Security-CVE-2026-93698-Vulnerability-in-Multilang-Adminbin-September-29-2026"
},
{
"url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
},
{
"url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
},
{
"url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
},
{
"url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
},
{
"url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-93698",
"datePublished": "2026-10-02T06:20:33.663Z",
"dateReserved": "2026-09-18T15:00:00.595Z",
"dateUpdated": "2026-10-02T18:14:48.415Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87899 (GCVE-0-2026-87899)
Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 03:55
VLAI
EPSS
VEX
Summary
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 00:00 UTC
CWE
- CWE-250 - Execution with Unnecessary Privileges
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | cPanel |
Affected:
11.120.0.0 , < 11.134.0.57
(semver)
Affected: 11.136.0.0 , < 11.136.0.41 (semver) Affected: 11.138.0.0 , < 11.138.0.8 (semver) Unaffected: 11.134.0.57 , < 11.134.0.57 (semver) Unaffected: 11.136.0.41 , < 11.136.0.41 (semver) Unaffected: 11.138.0.8 , < 11.138.0.8 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87899",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T03:55:45.144Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.134.0.57",
"status": "affected",
"version": "11.120.0.0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.41",
"status": "affected",
"version": "11.136.0.0",
"versionType": "semver"
},
{
"lessThan": "11.138.0.8",
"status": "affected",
"version": "11.138.0.0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.57",
"status": "unaffected",
"version": "11.134.0.57",
"versionType": "semver"
},
{
"lessThan": "11.136.0.41",
"status": "unaffected",
"version": "11.136.0.41",
"versionType": "semver"
},
{
"lessThan": "11.138.0.8",
"status": "unaffected",
"version": "11.138.0.8",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ali Mustafa (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-250",
"description": "CWE-250 Execution with Unnecessary Privileges",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:52:47.216Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43591715125271"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-87899",
"datePublished": "2026-09-23T19:52:47.216Z",
"dateReserved": "2026-09-09T15:00:00.573Z",
"dateUpdated": "2026-09-24T03:55:45.144Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68492 (GCVE-0-2026-68492)
Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 14:28
VLAI
EPSS
VEX
Summary
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 14:28 UTC
CWE
- CWE-426 - Untrusted Search Path
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | Plesk |
Affected:
18.0.34 , < 18.0.80.8
(semver)
Affected: 18.0.81 , < 18.0.81.1 (semver) |
|
| WebPros | Plesk extension "Plesk RESTful API" |
Affected:
2.4.2 , < 2.4.7
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68492",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:28:28.100954Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:28:36.450Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.80.8",
"status": "affected",
"version": "18.0.34",
"versionType": "semver"
},
{
"lessThan": "18.0.81.1",
"status": "affected",
"version": "18.0.81",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Plesk extension \"Plesk RESTful API\"",
"vendor": "WebPros",
"versions": [
{
"lessThan": "2.4.7",
"status": "affected",
"version": "2.4.2",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ali Mustafa (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the \"Plesk RESTful API\" extension from 2.4.2 before 2.4.7."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-426",
"description": "CWE-426 Untrusted Search Path",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:52:47.192Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43644058632983"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68492",
"datePublished": "2026-09-23T19:52:47.192Z",
"dateReserved": "2026-07-30T15:00:00.609Z",
"dateUpdated": "2026-09-24T14:28:36.450Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68490 (GCVE-0-2026-68490)
Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 14:28
VLAI
EPSS
VEX
Summary
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 14:28 UTC
CWE
- CWE-732 - Incorrect Permission Assignment for Critical Resource
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | cPanel |
Affected:
11.120.0.0 , < 11.134.0.57
(semver)
Affected: 11.136.0.0 , < 11.136.0.41 (semver) Affected: 11.138.0.0 , < 11.138.0.8 (semver) Unaffected: 11.134.0.57 , < 11.134.0.57 (semver) Unaffected: 11.136.0.41 , < 11.136.0.41 (semver) Unaffected: 11.138.0.8 , < 11.138.0.8 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68490",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:28:48.363650Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:28:56.203Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.134.0.57",
"status": "affected",
"version": "11.120.0.0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.41",
"status": "affected",
"version": "11.136.0.0",
"versionType": "semver"
},
{
"lessThan": "11.138.0.8",
"status": "affected",
"version": "11.138.0.0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.57",
"status": "unaffected",
"version": "11.134.0.57",
"versionType": "semver"
},
{
"lessThan": "11.136.0.41",
"status": "unaffected",
"version": "11.136.0.41",
"versionType": "semver"
},
{
"lessThan": "11.138.0.8",
"status": "unaffected",
"version": "11.138.0.8",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Ali Mustafa (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-732",
"description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:52:47.162Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43502940099991"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68490",
"datePublished": "2026-09-23T19:52:47.162Z",
"dateReserved": "2026-07-30T15:00:00.609Z",
"dateUpdated": "2026-09-24T14:28:56.203Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87900 (GCVE-0-2026-87900)
Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-23 20:05
VLAI
EPSS
VEX
Summary
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 20:05 UTC
CWE
- CWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | WP Toolkit for cPanel |
Affected:
0 , ≤ 6.11.2-10794
(semver)
Unaffected: 6.11.3-10850 , < 6.11.3-10850 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87900",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T20:05:51.395539Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T20:05:57.710Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "WP Toolkit for cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThanOrEqual": "6.11.2-10794",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "6.11.3-10850",
"status": "unaffected",
"version": "6.11.3-10850",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ali Mustafa (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-88",
"description": "CWE-88 Improper Neutralization of Argument Delimiters in a Command (\u0027Argument Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:52:47.153Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43597969409943"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-87900",
"datePublished": "2026-09-23T19:52:47.153Z",
"dateReserved": "2026-09-09T15:00:00.574Z",
"dateUpdated": "2026-09-23T20:05:57.710Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87898 (GCVE-0-2026-87898)
Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-23 20:06
VLAI
EPSS
VEX
Summary
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 20:06 UTC
CWE
- CWE-78 - OS Command Injection
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | Plesk extension "Site Import" |
Affected:
1.6.6 , ≤ 1.12.1
(semver)
Unaffected: 1.12.2 , < 1.12.2 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87898",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T20:06:19.972843Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T20:06:28.175Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Plesk extension \"Site Import\"",
"vendor": "WebPros",
"versions": [
{
"lessThanOrEqual": "1.12.1",
"status": "affected",
"version": "1.6.6",
"versionType": "semver"
},
{
"lessThan": "1.12.2",
"status": "unaffected",
"version": "1.12.2",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ali Mustafa (rz1027)"
}
],
"descriptions": [
{
"lang": "en",
"value": "OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:52:47.081Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43641151026583"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-87898",
"datePublished": "2026-09-23T19:52:47.081Z",
"dateReserved": "2026-09-09T15:00:00.573Z",
"dateUpdated": "2026-09-23T20:06:28.175Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68491 (GCVE-0-2026-68491)
Vulnerability from cvelistv5 – Published: 2026-09-15 20:59 – Updated: 2026-09-16 18:04
VLAI
EPSS
VEX
Summary
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:04 UTC
CWE
- CWE-59 - Improper Link Resolution Before File Access ('Link Following')
Assigner
References
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68491",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:04:00.594086Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:04:11.685Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "SolusVM",
"vendor": "Webpros",
"versions": [
{
"lessThan": "1.30.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "RackNerd"
}
],
"descriptions": [
{
"lang": "en",
"value": "An insufficient check allowed for the overwrite of arbitrary files via a symlink."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T20:59:50.186Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://docs.solusvm.com/en/solusvm1/release-notes/stable-branch/v1.30/#13015"
},
{
"url": "https://docs.solusvm.com/en/solusvm1/release-notes/mainline-branch/v1.30/#13015"
},
{
"url": "https://support.solusvm.com/hc/en-us/articles/43503583489687-CVE-2026-68491-Vulnerability-in-SolusVM-1-allows-Guest-to-Host-privilege-escalation"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68491",
"datePublished": "2026-09-15T20:59:50.186Z",
"dateReserved": "2026-07-30T15:00:00.609Z",
"dateUpdated": "2026-09-16T18:04:11.685Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68489 (GCVE-0-2026-68489)
Vulnerability from cvelistv5 – Published: 2026-09-14 20:53 – Updated: 2026-09-15 13:28
VLAI
EPSS
VEX
Summary
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 13:28 UTC
CWE
- CWE-96 - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | Plesk extension "Ruby" |
Affected:
0 , < 1.6.6
(semver)
|
|
| WebPros | Plesk extension "Node.js Toolkit" |
Affected:
0 , < 2.5.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68489",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:28:42.978491Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:28:53.581Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk extension \"Ruby\"",
"vendor": "WebPros",
"versions": [
{
"lessThan": "1.6.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Plesk extension \"Node.js Toolkit\"",
"vendor": "WebPros",
"versions": [
{
"lessThan": "2.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d1n4h"
}
],
"descriptions": [
{
"lang": "en",
"value": "Static Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-96",
"description": "CWE-96 Improper Neutralization of Directives in Statically Saved Code (\u0027Static Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T20:53:05.644Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43473204617239"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68489",
"datePublished": "2026-09-14T20:53:05.644Z",
"dateReserved": "2026-07-30T15:00:00.609Z",
"dateUpdated": "2026-09-15T13:28:53.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67399 (GCVE-0-2026-67399)
Vulnerability from cvelistv5 – Published: 2026-09-14 20:53 – Updated: 2026-09-15 13:28
VLAI
EPSS
VEX
Summary
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 13:28 UTC
CWE
- CWE-502 - Deserialization of Untrusted Data
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67399",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:28:16.542784Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:28:24.720Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WHMCS",
"vendor": "WebPros",
"versions": [
{
"lessThan": "9.0.8",
"status": "affected",
"version": "9.0.0",
"versionType": "semver"
},
{
"lessThan": "8.13.7",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "azizk (@realazizk)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T20:53:05.620Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://help.whmcs.com/m/125386/l/2118034-cve-2026-67399-whmcs-security-update-2026-09-03"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67399",
"datePublished": "2026-09-14T20:53:05.620Z",
"dateReserved": "2026-07-29T15:00:02.294Z",
"dateUpdated": "2026-09-15T13:28:24.720Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65639 (GCVE-0-2026-65639)
Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:19
VLAI
EPSS
VEX
Summary
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 18:19 UTC
CWE
- CWE-78 - OS Command Injection
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | ConfigServer Security & Firewall |
Affected:
2.15 , < 16.30
(semver)
|
|
| ConfigServer | ConfigServer Security & Firewall |
Affected:
2.15 , < *
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65639",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T18:19:30.960257Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T18:19:47.504Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "WebPros",
"versions": [
{
"lessThan": "16.30",
"status": "affected",
"version": "2.15",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "ConfigServer",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "2.15",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OS command injection in the advanced-rule parser of ConfigServer Security \u0026 Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.\n\nThe vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security \u0026 Firewall (CSF) may also be affected and should be evaluated independently."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.5,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T16:24:52.871Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43387923160343-Security-CVE-2026-65639-CSF-Security-Release"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65639",
"datePublished": "2026-09-10T16:24:52.871Z",
"dateReserved": "2026-07-22T15:00:06.103Z",
"dateUpdated": "2026-09-10T18:19:47.504Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68487 (GCVE-0-2026-68487)
Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:08
VLAI
EPSS
VEX
Summary
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 18:08 UTC
CWE
- CWE-36 - Absolute Path Traversal
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68487",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T18:08:44.436403Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T18:08:51.400Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThanOrEqual": "18.0.80.6",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "18.0.79.10",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Path traversal in Plesk\u0027s Backup Manager causes arbitrary file write as root by an authenticated customer."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-36",
"description": "CWE-36 Absolute Path Traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T16:24:52.847Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68487",
"datePublished": "2026-09-10T16:24:52.847Z",
"dateReserved": "2026-07-30T15:00:00.608Z",
"dateUpdated": "2026-09-10T18:08:51.400Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65638 (GCVE-0-2026-65638)
Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:19
VLAI
EPSS
VEX
Summary
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 18:19 UTC
CWE
- CWE-78 - OS Command Injection
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | ConfigServer Security & Firewall |
Affected:
14.00 , < 16.30
(semver)
|
|
| ConfigServer | ConfigServer Security & Firewall |
Affected:
14.00 , < *
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65638",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T18:19:11.551770Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T18:19:18.373Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "WebPros",
"versions": [
{
"lessThan": "16.30",
"status": "affected",
"version": "14.00",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "ConfigServer",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "14.00",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper escaping of a request URL in ConfigServer Security \u0026 Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.\n\nThe vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security \u0026 Firewall (CSF) may also be affected and should be evaluated independently."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T16:24:52.785Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43387915588375-Security-CVE-2026-65638-CSF-Security-Release"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65638",
"datePublished": "2026-09-10T16:24:52.785Z",
"dateReserved": "2026-07-22T15:00:06.103Z",
"dateUpdated": "2026-09-10T18:19:18.373Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68488 (GCVE-0-2026-68488)
Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:18
VLAI
EPSS
VEX
Summary
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 18:18 UTC
CWE
- CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68488",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T18:18:44.361511Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T18:18:54.741Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThanOrEqual": "18.0.80.6",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "18.0.79.10",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-367",
"description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T16:24:52.781Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-68488",
"datePublished": "2026-09-10T16:24:52.781Z",
"dateReserved": "2026-07-30T15:00:00.609Z",
"dateUpdated": "2026-09-10T18:18:54.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67401 (GCVE-0-2026-67401)
Vulnerability from cvelistv5 – Published: 2026-09-09 15:49 – Updated: 2026-09-10 03:56
VLAI
EPSS
VEX
Summary
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-09 00:00 UTC
CWE
- CWE-89 - SQL Injection
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67401",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T03:56:49.614Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.134.0.55",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.39",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.138.0.4",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.138.1.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.110.0.143",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component"
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 SQL Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T15:49:40.391Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67401",
"datePublished": "2026-09-09T15:49:40.391Z",
"dateReserved": "2026-07-29T15:00:02.294Z",
"dateUpdated": "2026-09-10T03:56:49.614Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67397 (GCVE-0-2026-67397)
Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-04 19:47
VLAI
EPSS
VEX
Summary
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 19:46 UTC
CWE
- CWE-22 - Path Traversal
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67397",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T19:46:57.842520Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T19:47:09.558Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.79.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "18.0.80.5",
"status": "affected",
"version": "18.0.80",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Path Traversal",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T23:57:15.922Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/43070000520855-Vulnerability-CVE-2026-67397-Arbitrary-code-execution-as-root-in-Plesk"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67397",
"datePublished": "2026-09-03T23:57:15.922Z",
"dateReserved": "2026-07-29T15:00:02.293Z",
"dateUpdated": "2026-09-04T19:47:09.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67402 (GCVE-0-2026-67402)
Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-04 19:47
VLAI
EPSS
VEX
Summary
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 19:47 UTC
CWE
- CWE-552 - Files or Directories Accessible to External Parties
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | ConfigServer Security & Firewall |
Affected:
14.02 , < 16.31
(semver)
|
|
| ConfigServer | ConfigServer Security & Firewall |
Affected:
14.02 , < *
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67402",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T19:47:27.442444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T19:47:36.330Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "WebPros",
"versions": [
{
"lessThan": "16.31",
"status": "affected",
"version": "14.02",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ConfigServer Security \u0026 Firewall",
"vendor": "ConfigServer",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "14.02",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An insecure Apache configuration in ConfigServer Security \u0026 Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-552",
"description": "CWE-552 Files or Directories Accessible to External Parties",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T23:57:15.878Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026"
}
],
"workarounds": [
{
"lang": "en",
"value": "Disable Messenger v3 by setting MESSENGERV3 = \"0\" until version 16.31 can be installed. This is the shipped default."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67402",
"datePublished": "2026-09-03T23:57:15.878Z",
"dateReserved": "2026-07-29T15:00:02.294Z",
"dateUpdated": "2026-09-04T19:47:36.330Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67398 (GCVE-0-2026-67398)
Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-14 20:53
VLAI
EPSS
VEX
Summary
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 19:47 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67398",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T19:47:54.274188Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T19:48:08.664Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WHMCS",
"vendor": "WebPros",
"versions": [
{
"lessThan": "8.12.2",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThan": "8.13.7",
"status": "affected",
"version": "8.13.0",
"versionType": "semver"
},
{
"lessThan": "9.0.8",
"status": "affected",
"version": "9.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "boomerang"
}
],
"descriptions": [
{
"lang": "en",
"value": "Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer\u0027s data via 2Checkout payment gateway\u0027s endpoint under specific conditions."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T20:53:05.678Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03"
}
],
"workarounds": [
{
"lang": "en",
"value": "Deactivate 2Checkout payment gateway."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67398",
"datePublished": "2026-09-03T23:57:15.810Z",
"dateReserved": "2026-07-29T15:00:02.294Z",
"dateUpdated": "2026-09-14T20:53:05.678Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65643 (GCVE-0-2026-65643)
Vulnerability from cvelistv5 – Published: 2026-09-01 02:07 – Updated: 2026-09-02 03:55
VLAI
EPSS
VEX
Summary
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-01 00:00 UTC
CWE
- CWE-95 - Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65643",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-01T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T03:55:20.753Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.110.0.141",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.53",
"status": "affected",
"version": "11.112.0.0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.37",
"status": "affected",
"version": "11.136.0.0",
"versionType": "semver"
},
{
"lessThan": "11.138.0.2",
"status": "affected",
"version": "11.138.0.0",
"versionType": "semver"
},
{
"lessThan": "11.138.1.7",
"status": "affected",
"version": "11.138.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Ali Mustafa"
}
],
"descriptions": [
{
"lang": "en",
"value": "Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-95",
"description": "CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T02:07:41.778Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Park-API-Vulnerability-August-27-2026"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65643",
"datePublished": "2026-09-01T02:07:41.778Z",
"dateReserved": "2026-07-22T15:00:06.103Z",
"dateUpdated": "2026-09-02T03:55:20.753Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67394 (GCVE-0-2026-67394)
Vulnerability from cvelistv5 – Published: 2026-09-01 02:07 – Updated: 2026-09-01 13:14
VLAI
EPSS
VEX
Summary
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-01 13:14 UTC
CWE
- CWE-78 - OS Command Injection
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67394",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-01T13:14:29.944649Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T13:14:45.804Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.79.9",
"status": "affected",
"version": "18.0.34",
"versionType": "semver"
},
{
"lessThan": "18.0.80.5",
"status": "affected",
"version": "18.0.80",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Aziz Knani"
}
],
"descriptions": [
{
"lang": "en",
"value": "A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T02:07:41.777Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root"
}
],
"workarounds": [
{
"lang": "en",
"value": "Disable shell access for customers or resellers if it is not required (make sure their service plan does not allow to change it)"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-67394",
"datePublished": "2026-09-01T02:07:41.777Z",
"dateReserved": "2026-07-29T15:00:02.293Z",
"dateUpdated": "2026-09-01T13:14:45.804Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65646 (GCVE-0-2026-65646)
Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-09-11 17:16
VLAI
EPSS
VEX
Summary
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-27 13:01 UTC
CWE
- CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65646",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-27T13:01:50.922762Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T15:04:11.031Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.79.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "18.0.80.7",
"status": "affected",
"version": "18.0.80",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Aziz Knani"
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization of special elements in in Plesk\u0027s DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T17:16:03.698Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42877023875351-Vulnerability-CVE-2026-65646-in-Plesk-s-DNS-zone-management-functionality"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65646",
"datePublished": "2026-08-26T21:21:41.144Z",
"dateReserved": "2026-07-22T15:00:06.104Z",
"dateUpdated": "2026-09-11T17:16:03.698Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65642 (GCVE-0-2026-65642)
Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-08-27 18:07
VLAI
EPSS
VEX
Summary
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-27 18:03 UTC
CWE
- CWE-639 - Insecure Direct Object Reference (IDOR)
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65642",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-27T18:03:28.894998Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T18:07:19.708Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThanOrEqual": "18.0.79.7",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "18.0.80.4",
"status": "affected",
"version": "18.0.80",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Aziz Knani"
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers\u0027 databases."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Insecure Direct Object Reference (IDOR)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T21:21:41.122Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42844242102679-Vulnerability-CVE-2026-65642-in-Plesk-s-database-management-interface"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65642",
"datePublished": "2026-08-26T21:21:41.122Z",
"dateReserved": "2026-07-22T15:00:06.103Z",
"dateUpdated": "2026-08-27T18:07:19.708Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-65647 (GCVE-0-2026-65647)
Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-08-27 17:59
VLAI
EPSS
VEX
Summary
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-27 17:59 UTC
CWE
- CWE-59 - Improper Link Resolution Before File Access ('Link Following')
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | Plesk Migrator |
Affected:
0 , < 2.36.0
(semver)
|
|
| WebPros | Plesk Site Import |
Affected:
0 , < 1.12.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-65647",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-27T17:59:40.758788Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:59:51.351Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk Migrator",
"vendor": "WebPros",
"versions": [
{
"lessThan": "2.36.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Plesk Site Import",
"vendor": "WebPros",
"versions": [
{
"lessThan": "1.12.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T21:21:41.033Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-65647",
"datePublished": "2026-08-26T21:21:41.033Z",
"dateReserved": "2026-07-22T15:00:06.104Z",
"dateUpdated": "2026-08-27T17:59:51.351Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64639 (GCVE-0-2026-64639)
Vulnerability from cvelistv5 – Published: 2026-08-12 15:31 – Updated: 2026-08-14 18:29
VLAI
EPSS
VEX
Summary
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-12 16:07 UTC
CWE
- CWE-266 - Incorrect Privilege Assignment
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-64639",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T16:07:43.248382Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T18:29:23.333Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.79.6",
"status": "affected",
"version": "18.0.52",
"versionType": "semver"
},
{
"lessThan": "18.0.80.2",
"status": "affected",
"version": "18.0.80.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Aziz Knani"
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "CWE-266 Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T15:31:45.624Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42521305418903-Vulnerability-CVE-2026-64639-Privilege-Escalation-via-Database-Cloning-in-Plesk"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-64639",
"datePublished": "2026-08-12T15:31:45.624Z",
"dateReserved": "2026-07-20T15:00:00.697Z",
"dateUpdated": "2026-08-14T18:29:23.333Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64637 (GCVE-0-2026-64637)
Vulnerability from cvelistv5 – Published: 2026-08-07 17:57 – Updated: 2026-08-07 18:25
VLAI
EPSS
VEX
Summary
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-07 18:24 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-64637",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-07T18:24:11.245542Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T18:25:40.293Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.80.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T17:57:25.500Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42432168683799"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-64637",
"datePublished": "2026-08-07T17:57:25.500Z",
"dateReserved": "2026-07-20T15:00:00.696Z",
"dateUpdated": "2026-08-07T18:25:40.293Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64636 (GCVE-0-2026-64636)
Vulnerability from cvelistv5 – Published: 2026-08-07 17:57 – Updated: 2026-08-07 18:23
VLAI
EPSS
VEX
Summary
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Severity
7.7 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-07 18:23 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-64636",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-07T18:23:29.520962Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T18:23:52.542Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.80.1",
"status": "affected",
"version": "18.0.51",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T17:57:25.451Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42431868205079"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-64636",
"datePublished": "2026-08-07T17:57:25.451Z",
"dateReserved": "2026-07-20T15:00:00.696Z",
"dateUpdated": "2026-08-07T18:23:52.542Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-58048 (GCVE-0-2026-58048)
Vulnerability from cvelistv5 – Published: 2026-07-31 16:35 – Updated: 2026-08-07 18:00
VLAI
EPSS
VEX
Summary
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-31 00:00 UTC
CWE
- CWE-89 - SQL Injection
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | cPanel |
Affected:
0 , < 11.110.0.137
(semver)
Affected: 0 , < 11.126.0.78 (semver) Affected: 0 , < 11.134.0.48 (semver) Affected: 0 , < 11.136.0.32 (semver) Affected: 0 , < 11.137.9999.99 (semver) Affected: 0 , < 11.118.0.71 (semver) |
|
| WebPros | WP Squared |
Affected:
0 , < 11.138.1.6
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-58048",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-31T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-01T03:56:21.794Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.110.0.137",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.126.0.78",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.48",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.32",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.137.9999.99",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.118.0.71",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WP Squared",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.138.1.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Vincent55 Yang"
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 SQL Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T18:00:28.533Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation"
},
{
"url": "https://docs.cpanel.net/changelogs/138-change-log"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-58048",
"datePublished": "2026-07-31T16:35:56.665Z",
"dateReserved": "2026-06-27T15:00:00.780Z",
"dateUpdated": "2026-08-07T18:00:28.533Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-58047 (GCVE-0-2026-58047)
Vulnerability from cvelistv5 – Published: 2026-07-31 16:35 – Updated: 2026-08-07 18:00
VLAI
EPSS
VEX
Summary
HTTP Smuggling in cPanel allows potential leak of credentials.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-31 17:17 UTC
CWE
- CWE-444 - HTTP Request Smuggling
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WebPros | cPanel |
Affected:
0 , < 11.110.0.137
(semver)
Affected: 0 , < 11.126.0.78 (semver) Affected: 0 , < 11.134.0.48 (semver) Affected: 0 , < 11.136.0.32 (semver) Affected: 0 , < 11.137.9999.99 (semver) Affected: 0 , < 11.118.0.71 (semver) |
|
| WebPros | WP Squared |
Affected:
0 , < 11.138.1.6
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-58047",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-31T17:17:29.381244Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-31T17:17:56.499Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "cPanel",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.110.0.137",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.126.0.78",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.134.0.48",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.136.0.32",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.137.9999.99",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "11.118.0.71",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WP Squared",
"vendor": "WebPros",
"versions": [
{
"lessThan": "11.138.1.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Vincent55 Yang"
}
],
"descriptions": [
{
"lang": "en",
"value": "HTTP Smuggling in cPanel allows potential leak of credentials."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-444",
"description": "CWE-444 HTTP Request Smuggling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T18:00:48.776Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.cpanel.net/hc/en-us/articles/42285024734743-Security-CVE-2026-58047-HTTP-Request-Smuggling"
},
{
"url": "https://docs.cpanel.net/changelogs/138-change-log"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-58047",
"datePublished": "2026-07-31T16:35:56.600Z",
"dateReserved": "2026-06-27T15:00:00.780Z",
"dateUpdated": "2026-08-07T18:00:48.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-58046 (GCVE-0-2026-58046)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:02 – Updated: 2026-08-14 15:02
VLAI
EPSS
VEX
Summary
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
Severity
9.9 (Critical)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 12:38 UTC
CWE
- CWE-89 - SQL Injection
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-58046",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T12:38:10.851144Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T12:38:20.183Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Plesk",
"vendor": "WebPros",
"versions": [
{
"lessThan": "18.0.79.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 SQL Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T15:02:39.515Z",
"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"shortName": "hackerone"
},
"references": [
{
"url": "https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
"assignerShortName": "hackerone",
"cveId": "CVE-2026-58046",
"datePublished": "2026-07-30T06:02:50.017Z",
"dateReserved": "2026-06-27T15:00:00.780Z",
"dateUpdated": "2026-08-14T15:02:39.515Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}