Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-52206 | ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage. ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage. NVD description · AI analysis pending | 4.7 | <1% |
| — | ||
| CVE-2023-46818 | An issue was discovered in ISPConfig before 3.2.11p1. An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. NVD description · AI analysis pending | 7.2 | 16% |
| — | ||
| CVE-2021-3021 | ISPConfig before 3.2.2 allows SQL injection. ISPConfig before 3.2.2 allows SQL injection. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-9398 | ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection. ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2018-17984 | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access. NVD description · AI analysis pending | 7.8 | 3% | PoC ×2 |
| — | |
| CVE-2017-17384 | ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. NVD description · AI analysis pending | 8.8 | 1% |
| — |