DirectAdmin's vulnerability profile centers on a single widely deployed web hosting control panel that manages server administration and customer account operations across numerous hosting providers. Its exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, and input-validation flaws, reflecting the complexity of a user-facing administrative interface, and the vendor's disclosures frequently acquire public exploit code. Defenders should prioritize patching this control-panel software and restrict its network exposure, as internet-facing instances represent a direct path to server compromise; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Directadmin over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9625HIGH JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. | Mar 7, 2019 | 8.8 | 32 | NO | YES |
CVE-2019-11193MEDIUM The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, | Apr 30, 2019 | 6.1 | 30 | NO | YES |
CVE-2017-18045CRITICAL JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspeci | Jan 21, 2018 | 9.8 | 29 | NO | NO |
CVE-2025-56551HIGH An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via | Oct 3, 2025 | 8.2 | 26 | NO | NO |
CVE-2009-1526MEDIUM JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a r | May 5, 2009 | 6.9 | 26 | NO | YES |
CVE-2009-2216MEDIUM Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=adva | Jun 25, 2009 | 6.1 | 25 | NO | YES |
CVE-2006-5983MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user par | Nov 20, 2006 | 6.0 | 25 | NO | YES |
CVE-2011-5033MEDIUM Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (c | Dec 29, 2011 | 4.4 | 24 | NO | YES |
CVE-2009-1525HIGH CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action. | May 5, 2009 | 8.5 | 22 | NO | NO |
CVE-2007-1508MEDIUM Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vecto | Mar 20, 2007 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Directadmin.
Media articles that mention a CVE ID that affects a product developed by Directadmin — matched by CVE ID, not by vendor name.