Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cpanel

First CVE: Aug 18, 2003Active for: 23 yearsTotal CVEs: 428
57.6
VTI Score
TOP TARGET

cPanel's vulnerability footprint concentrates in a narrow set of widely deployed web hosting management platforms—chiefly cPanel itself and WebHost Manager—that control server configuration and user account administration across millions of hosted domains and server instances. Despite this concentrated product scope, the vendor commands high prominence in the landscape due to the central administrative role these tools play in shared hosting infrastructure and their internet-facing exposure. The recurring weakness classes center on web application input handling, particularly cross-site scripting and improper input validation, alongside occasional exposure of sensitive configuration and credential data, reflecting the authentication and form-processing demands of administrative dashboards. Vulnerabilities affecting this vendor demonstrate a moderate tendency toward public exploit availability, consistent with the appeal of web administration interfaces for post-compromise lateral movement and privilege escalation. Defenders should track cPanel advisories closely, maintain strict access controls on administrative endpoints, and prioritize patching to limit both direct exploitation and post-breach movement within hosted environments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
428
Total CVEs
More Total CVEs than 100% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Cpanel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2003
22 years ago
Most Recent CVE
Apr 29, 2026
86 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (428 CVEs).

428 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-41940CRITICAL
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the
Apr 29, 20269.899YESYES
CVE-2023-29489MEDIUM
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.
Apr 27, 20236.168NOYES
CVE-2004-1769HIGH
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the us
Mar 11, 200410.053NOYES
CVE-2003-1425HIGH
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
Dec 31, 200310.040NOYES
CVE-2004-1770HIGH
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
Mar 11, 200410.039NOYES
CVE-2004-0490HIGH
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to f
Aug 18, 20047.235NOYES
CVE-2008-2478HIGH
scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell
May 28, 20088.534NOYES
CVE-2004-1875HIGH
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html,
Mar 30, 20049.334NOYES
CVE-2006-5014HIGH
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
Sep 27, 20068.832NOYES
CVE-2020-26108CRITICAL
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
Sep 25, 20209.831NONO
View all 428 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products428 CVEs
13%
57%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local88 (20.6%)
Network297 (69.4%)
Unknown42 (9.8%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low370 (86.4%)
High16 (3.7%)
Unknown42 (9.8%)
User Interaction
None283 (66.1%)
Unknown42 (9.8%)
Required103 (24.1%)
Privileges Required
Low241 (56.3%)
High36 (8.4%)
None109 (25.5%)
Unknown42 (9.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (428 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 99th percentile
Metasploit
1 CVE
0.2% of CVEs· 97th percentile
Nuclei
2 CVEs
0.5% of CVEs· 95th percentile
ExploitDB
28 CVEs
6.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cpanel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cpanel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cpanel's Products

View all 2 CNAs →

Top CWEs