21 Total CVEs
21 AI Analyzed
1 CISA KEV
9 Critical

Profile

4.8% ended up actively exploited 1 of 21 added to CISA KEV
43% rated critical (CVSS 9.0+) 9 critical, 12 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

21 CVEs in the last 12 months

Products

  • Plesk8
  • cPanel2
  • WHMCS1
  • Plesk Migrator and Plesk Site Import1
  • WordPress Toolkit1
  • functionality1
  • cPanel and WHM1

7 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-21 of 21 CVEs
CVE-2026-67398
Analyzed
8.2
WebPros WHMCS

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all...

2026-09-04
CVE-2026-67397
Analyzed
8.5
WebPros Plesk

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

2026-09-04
CVE-2026-65647
Analyzed
8.7
WebPros Plesk Migrator and Plesk Site Import

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root

2026-08-27
CVE-2026-65646
Analyzed
8.7
WebPros Plesk

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges

2026-08-27
CVE-2026-65643
Analyzed
8.7
WebPros cPanel

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

2026-09-01
CVE-2026-65642
Analyzed
8.6
WebPros Plesk

Insecure direct object reference in Plesk 18

2026-08-27
CVE-2026-64637
Analyzed
9.9
WebPros Plesk

Plesk before 18.0.80.1 contains an improper privilege management vulnerability in its XML-RPC API that allows resellers to escalate to administrative...

2026-08-08
CVE-2026-64636
Analyzed
7.7
WebPros Plesk

An SQL injection vulnerability in Plesk Obsidian up to 18

2026-08-09
CVE-2026-58048
Analyzed
9.4
WebPros cPanel

A SQL injection vulnerability in cPanel allows authenticated users with low privileges to execute arbitrary SQL commands in the root context when rena...

2026-08-01
CVE-2026-58046
Analyzed
9.9
WebPros Plesk

A blind SQL injection vulnerability in the Plesk XML-RPC API allows an authenticated low-privileged user to read arbitrary data from the Plesk databas...

2026-07-30
CVE-2026-56843
Analyzed
9.9
WebPros Plesk

WebPros Plesk contains an authorization flaw in the XML-RPC API that allows authenticated customers to access cross-tenant data and plaintext FTP cred...

2026-07-08
CVE-2026-48614
Analyzed
9.9
WebPros Plesk

An improper authorization vulnerability in the Plesk XML API allows authenticated users to inject configuration directives, leading to arbitrary file...

2026-07-07
CVE-2026-47365
Analyzed
9.9
WebPros WordPress Toolkit

An argument injection vulnerability in WordPress Toolkit allows authenticated users to bypass cross-tenant authorization and execute arbitrary CLI com...

2026-06-12
CVE-2026-44962
Analyzed
9.9
WebPros functionality

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XP...

2026-05-30
CVE-2026-41940
KEV Analyzed
9.8
WebPros cPanel and WHM

An authentication bypass vulnerability in the cPanel and WHM login flow allows unauthenticated remote attackers to gain unauthorized access to the con...

2026-04-30
CVE-2026-32993
Analyzed
8.3
WebPros Multiple Products

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HT...

2026-05-14
CVE-2026-32992
Analyzed
8.2
WebPros Multiple Products

SSL verification is disabled in the DNS Cluster system

2026-05-14
CVE-2026-29205
Analyzed
8.6
WebPros Multiple Products

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoint...

2026-05-14
CVE-2026-29204
Analyzed
9.1
WebPros Multiple Products

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without an...

2026-05-13
CVE-2026-29203
Analyzed
8.8
WebPros Multiple Products

A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or dire...

2026-05-09
CVE-2026-29202
Analyzed
8.8
WebPros Multiple Products

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already auth...

2026-05-09