Vulnerabilities
384 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65643 | Authenticated eval injection in cPanel enables root code execution cPanel 11.138.0.0 and earlier contains an eval injection flaw (CWE-95) in which attacker-controlled input reaches dynamic code evaluation without proper neutralization. A remote attacker holding any authenticated account on a cPanel server, such as an ordinary hosting customer, can trigger the flaw with crafted input and no user interaction. Successful exploitation yields arbitrary code execution as root, meaning a single low-privilege tenant can compromise the entire server and every site hosted on it. All deployments running version 11.138.0.0 or earlier are affected, which at disclosure covers essentially all active cPanel servers given that this was the current release. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not in CISA KEV and EPSS assigns only a 0.9% probability of exploitation within 30 days. Do: Upgrade cPanel/WHM to a fixed release above 11.138.0.0 published under WebPros advisory AV26-861, prioritizing multi-tenant shared servers where any customer account can reach the vulnerable code. Until patched, restrict shell and feature access for untrusted accounts and review authentication logs and unexpected root-owned processes. No workaround is documented in the available data, so updating is the primary action. | 8.7 | <1% |
| massroughly hundreds of thousands of cPanel/WHM servers (millions of hosted sites on multi-tenant shared hosting) | ||
| CVE-2026-29205 +1 in the same advisory: …32992 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. NVD description · AI analysis pending | 8.6 group max | 8% |
| — | ||
| CVE-2026-41940 | Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE) CVE-2026-41940 is a critical missing-authentication flaw (CWE-306) in the login flow of WebPros cPanel & WHM (versions after 11.40) and WP2 (WordPress Squared) that lets unauthenticated remote attackers bypass authentication and gain unauthorized access to the control panel. Because no privileges, user interaction, or special conditions are required, any attacker who can reach the login endpoint over the network can attempt it. Beyond control-panel account takeover, public proofs of concept — including watchTowr's 'AuthBypass to RCE' exploit — show the flaw can be chained to remote code execution, and reporting indicates a single hosting customer could obtain root control of an entire shared server. Any hosting provider, MSP, reseller, or organization running cPanel/WHM or WP Squared is affected; cPanel is the dominant commercial hosting control panel, implying a very large installed base of shared-hosting servers and hosted domains. Exploitation is confirmed in the wild: CISA added it to the KEV on 2026-04-30 with known ransomware use, EPSS assigns a 98.5% probability of exploitation within 30 days (100th percentile), and multiple threat actors are actively exploiting it, including against government and MSP networks. Do: Patch immediately per WebPros' advisory — the source data does not specify fixed version numbers, so follow vendor instructions for exact patched releases; CISA KEV/BOD 22-01 requires federal agencies to apply mitigations or discontinue use by the stated deadline (reported as Sunday). Until patched, restrict access to the cPanel/WHM login interface (IP allowlisting, VPN, or limiting management-interface exposure) and hunt for indicators of compromise such as unexpected control-panel logins, new admin accounts, webshells, or ransomware artifacts. The referenced public PoCs can be used to validate whether your instances are exploitable. | 9.3 | 99% | KEV ransomware PoC ×5 |
| mass≈100,000+ internet-exposed cPanel/WHM servers, spanning tens of millions of hosted domains and millions of end users | |
| CVE-2025-66429 | An issue was discovered in cPanel 110 through 132. An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-29489 | An issue was discovered in cPanel before 11.109.9999.116. An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31. NVD description · AI analysis pending | 6.1 | 66% | PoC |
| — | |
| CVE-2021-38589 | In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588). In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588). NVD description · AI analysis pending | 8.1 group max | <1% |
| — | ||
| CVE-2021-31803 | cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-26267 +1 in the same advisory: …26266 | cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-29136 | In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). NVD description · AI analysis pending | 6.5 group max | 1% |
| — | ||
| CVE-2020-26098 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). NVD description · AI analysis pending | 9.8 group max | 3% |
| — | ||
| CVE-2020-12785 +1 in the same advisory: …12784 | cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540). cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540). NVD description · AI analysis pending | 8.1 group max | <1% |
| — | ||
| CVE-2020-10119 | cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). NVD description · AI analysis pending | 9.8 group max | 2% |
| — |