WebPros / WP Squared
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93029 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | CRITICAL | 9.0 | Oct 2, 2026 |
| CVE-2026-93697 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | CRITICAL | 9.0 | Oct 2, 2026 |
| CVE-2026-93698 | Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin. | CRITICAL | 9.9 | Oct 2, 2026 |
| CVE-2026-58048 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | CRITICAL | 9.4 | Jul 31, 2026 |
| CVE-2026-58047 | HTTP Smuggling in cPanel allows potential leak of credentials. | MEDIUM | 5.6 | Jul 31, 2026 |
| CVE-2026-29206 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | HIGH | 8.1 | May 13, 2026 |
| CVE-2026-32991 | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account. | HIGH | 7.1 | May 13, 2026 |
| CVE-2026-29205 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | HIGH | 8.6 | May 13, 2026 |
| CVE-2026-32992 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | HIGH | 8.2 | May 13, 2026 |
| CVE-2026-32993 | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header… | HIGH | 8.3 | May 13, 2026 |
| CVE-2026-29201 | Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is p… | HIGH | 8.6 | May 8, 2026 |
| CVE-2026-29202 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated… | MEDIUM | 5.3 | May 8, 2026 |
| CVE-2026-29203 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories.… | MEDIUM | 5.3 | May 8, 2026 |
Showing 1 to 13 of 13 CVEs