Skip to main content

Vendor/product archive

cpanel / whm CVEs

Beta · best-effort

5 CVEs tagged to cpanel / whm1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-41940

Published Apr 29, 2026

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to th…

CVSS 9.3 · Critical
evidence mentions
33
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2012-6449

Published Feb 10, 2020

The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11441

Published Jul 19, 2017

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1