cPanel / Whm
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-29205 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | HIGH | 8.6 | May 13, 2026 |
| CVE-2026-32992 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | HIGH | 8.2 | May 13, 2026 |
| CVE-2026-41940 KEV | WebPros cPanel and WHM Authentication Bypass via Login Flow | CRITICAL | 9.3 | Apr 29, 2026 |
| CVE-2012-6449 | The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | MEDIUM | 5.4 | Feb 10, 2020 |
| CVE-2017-11441 | The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 6… | MEDIUM | 5.4 | Jul 19, 2017 |
Showing 1 to 5 of 5 CVEs