CVE Browser

More filters (active)
CVE-2025-66430 CRITICAL

Plesk 18.0 has Incorrect Access Control.

CVSS 9.1 EPSS 0.55% Dec 12, 2025
CVE-2025-66431 HIGH

WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. T…

CVSS 7.8 EPSS 0.25% Dec 3, 2025
CVE-2025-49618 MEDIUM

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

CVSS 5.8 EPSS 0.40% Jul 3, 2025
CVE-2023-4931 HIGH

Uncontrolled search path element vulnerability in Plesk

CVSS 7.8 EPSS 0.25% Nov 27, 2023
CVE-2023-43784 HIGH

Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there i…

CVSS 7.5 EPSS 0.56% Sep 22, 2023
CVE-2023-0829 CRITICAL

Cross-Site Scripting (XSS) vulnerability in Plesk

CVSS 9.0 EPSS 0.58% Sep 20, 2023
CVE-2023-24044 MEDIUM

A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request h…

CVSS 6.1 EPSS 2.27% Jan 22, 2023
CVE-2022-45130 MEDIUM

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk…

CVSS 6.5 EPSS 0.35% Nov 10, 2022
CVE-2021-45008 HIGH

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that…

CVSS 8.8 EPSS 1.96% Feb 21, 2022
CVE-2021-45007 MEDIUM

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the ve…

CVSS 6.5 EPSS 0.73% Feb 20, 2022
CVE-2021-35976 MEDIUM

The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-6…

CVSS 6.1 EPSS 1.15% Sep 10, 2021
CVE-2020-11583 MEDIUM

A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET pa…

CVSS 6.1 EPSS 1.02% Aug 3, 2020
CVE-2020-11584 MEDIUM

A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parame…

CVSS 6.1 EPSS 0.91% Aug 3, 2020
CVE-2001-1222 MEDIUM

Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid accou…

CVSS 5.0 EPSS 1.60% Mar 15, 2002

Showing 1 to 14 CVEs · page 1