CVE-2025-65518 is a Denial of Service (DoS) vulnerability affecting Plesk Obsidian versions 8.0.1 through 18.0.73. An unauthenticated remote attacker can send a crafted request to the get_password.php endpoint, causing the web interface to continuously reload and become unavailable. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network attack vector, low complexity, and high impact on availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.1, < 18.0.73CPE matchmatch criteria | cpe:2.3:a:webpros:plesk_obsidian:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.