WebPros / Plesk
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-68492 | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitra… | HIGH | 8.7 | Sep 23, 2026 |
| CVE-2026-68487 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | CRITICAL | 9.9 | Sep 10, 2026 |
| CVE-2026-68488 | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file… | CRITICAL | 9.9 | Sep 10, 2026 |
| CVE-2026-67397 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | HIGH | 8.5 | Sep 3, 2026 |
| CVE-2026-67394 | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before… | CRITICAL | 9.0 | Sep 1, 2026 |
| CVE-2026-65646 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files… | CRITICAL | 9.9 | Aug 26, 2026 |
| CVE-2026-65642 | Plesk: Plesk: Information disclosure and data modification via Insecure Direct Object Reference | HIGH | 8.6 | Aug 26, 2026 |
| CVE-2026-64639 | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary… | CRITICAL | 9.3 | Aug 12, 2026 |
| CVE-2026-64637 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root use… | CRITICAL | 9.9 | Aug 7, 2026 |
| CVE-2026-64636 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel databas… | HIGH | 7.7 | Aug 7, 2026 |
| CVE-2026-58046 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Pl… | CRITICAL | 9.9 | Jul 30, 2026 |
| CVE-2026-56843 | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own,… | CRITICAL | 9.9 | Jul 8, 2026 |
| CVE-2026-48614 | Plesk: Plesk: Privilege escalation via improper authorization in XML API | CRITICAL | 9.9 | Jul 6, 2026 |
| CVE-2026-44962 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queri… | CRITICAL | 9.9 | May 29, 2026 |
Showing 1 to 14 of 14 CVEs