cPanel's vulnerability footprint concentrates in a narrow set of widely deployed web hosting management platforms—chiefly cPanel itself and WebHost Manager—that control server configuration and user account administration across millions of hosted domains and server instances. Despite this concentrated product scope, the vendor commands high prominence in the landscape due to the central administrative role these tools play in shared hosting infrastructure and their internet-facing exposure. The recurring weakness classes center on web application input handling, particularly cross-site scripting and improper input validation, alongside occasional exposure of sensitive configuration and credential data, reflecting the authentication and form-processing demands of administrative dashboards. Vulnerabilities affecting this vendor demonstrate a moderate tendency toward public exploit availability, consistent with the appeal of web administration interfaces for post-compromise lateral movement and privilege escalation. Defenders should track cPanel advisories closely, maintain strict access controls on administrative endpoints, and prioritize patching to limit both direct exploitation and post-breach movement within hosted environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpanel over time
Signals from CVEs in this vendor scope (428 CVEs).
428 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41940CRITICAL cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the | Apr 29, 2026 | 9.8 | 99 | YES | YES |
CVE-2023-29489MEDIUM An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11. | Apr 27, 2023 | 6.1 | 68 | NO | YES |
CVE-2004-1769HIGH The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the us | Mar 11, 2004 | 10.0 | 53 | NO | YES |
CVE-2003-1425HIGH guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | Dec 31, 2003 | 10.0 | 40 | NO | YES |
CVE-2004-1770HIGH The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter. | Mar 11, 2004 | 10.0 | 39 | NO | YES |
CVE-2004-0490HIGH cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to f | Aug 18, 2004 | 7.2 | 35 | NO | YES |
CVE-2008-2478HIGH scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell | May 28, 2008 | 8.5 | 34 | NO | YES |
CVE-2004-1875HIGH Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, | Mar 30, 2004 | 9.3 | 34 | NO | YES |
CVE-2006-5014HIGH Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin. | Sep 27, 2006 | 8.8 | 32 | NO | YES |
CVE-2020-26108CRITICAL cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). | Sep 25, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (428 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpanel.
Media articles that mention a CVE ID that affects a product developed by Cpanel — matched by CVE ID, not by vendor name.