📦 Cpanel

by Cpanel

🔍 What is Cpanel?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-26105

CRITICAL CVSS 9.8 Sep 25, 2020

CVE-2020-26105 is an authentication bypass vulnerability in cPanel's chkservd service that uses insecure test credentials on templated virtual machines. Attackers can exploit these hardcoded credentia...

CVE-2020-26108

CRITICAL CVSS 9.8 Sep 25, 2020

CVE-2020-26108 is a critical file-extension dispatching vulnerability in cPanel that allows remote attackers to execute arbitrary code. This affects cPanel web hosting control panel installations, pot...

CVE-2020-26098

CRITICAL CVSS 9.8 Sep 25, 2020

CVE-2020-26098 is a critical remote code execution vulnerability in cPanel's Exim filter path handling. Attackers can exploit this to execute arbitrary code on affected cPanel servers. This affects al...

CVE-2020-26100

CRITICAL CVSS 9.8 Sep 25, 2020

CVE-2020-26100 is a Jailshell escape vulnerability in cPanel's chsh command that allows authenticated users to break out of restricted shell environments. This affects cPanel installations before vers...

CVE-2025-66429

HIGH CVSS 8.8 Dec 11, 2025

A directory traversal vulnerability in cPanel's Team Manager API allows attackers to overwrite arbitrary files, potentially leading to privilege escalation to root. This affects cPanel installations v...

CVE-2021-38584

HIGH CVSS 7.2 Aug 11, 2021

This vulnerability allows XML External Entity (XXE) attacks through the WHM Locale Upload feature in cPanel. Attackers can exploit this to read arbitrary files from the server, potentially accessing s...

CVE-2021-38587

HIGH CVSS 7.5 Aug 11, 2021

This vulnerability in cPanel's fix-cpanel-perl script allows local attackers to create arbitrary temporary files due to improper handling of file creation. It affects cPanel installations before versi...

CVE-2021-38589

HIGH CVSS 8.1 Aug 11, 2021

This vulnerability in cPanel's fix-cpanel-perl script allows attackers to overwrite arbitrary files on the system. It affects cPanel installations before version 96.0.13, potentially enabling privileg...