Obsidian
Plesk · 4 CVEs
CVE-2025-49618
MEDIUM
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, re…
Jul 3, 2025
CVE-2023-24044
MEDIUM
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to…
Jan 22, 2023
CVE-2022-45130
MEDIUM
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obs…
Nov 10, 2022
CVE-2021-35976
MEDIUM
The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via t…
Sep 10, 2021
CVE-2020-11583
MEDIUM
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitra…
Aug 3, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-49618 | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint. | MEDIUM | 0.40% | Jul 3, 2025 |
| CVE-2023-24044 | A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request h… | MEDIUM | 2.27% | Jan 22, 2023 |
| CVE-2022-45130 | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk… | MEDIUM | 0.35% | Nov 10, 2022 |
| CVE-2021-35976 | The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-6… | MEDIUM | 1.15% | Sep 10, 2021 |
| CVE-2020-11583 | A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET pa… | MEDIUM | 1.02% | Aug 3, 2020 |
Showing 1 to 4 of 4 CVEs