Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Directadmin

First CVE: Nov 20, 2006Active for: 20 yearsTotal CVEs: 15
30.1
VTI Score
Low

DirectAdmin's vulnerability profile centers on a single widely deployed web hosting control panel that manages server administration and customer account operations across numerous hosting providers. Its exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, and input-validation flaws, reflecting the complexity of a user-facing administrative interface, and the vendor's disclosures frequently acquire public exploit code. Defenders should prioritize patching this control-panel software and restrict its network exposure, as internet-facing instances represent a direct path to server compromise; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Directadmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2006
19 years ago
Most Recent CVE
Oct 3, 2025
294 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9625HIGH
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
Mar 7, 20198.832NOYES
CVE-2019-11193MEDIUM
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this,
Apr 30, 20196.130NOYES
CVE-2017-18045CRITICAL
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspeci
Jan 21, 20189.829NONO
CVE-2025-56551HIGH
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via
Oct 3, 20258.226NONO
CVE-2009-1526MEDIUM
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a r
May 5, 20096.926NOYES
CVE-2009-2216MEDIUM
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=adva
Jun 25, 20096.125NOYES
CVE-2006-5983MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user par
Nov 20, 20066.025NOYES
CVE-2011-5033MEDIUM
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (c
Dec 29, 20114.424NOYES
CVE-2009-1525HIGH
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
May 5, 20098.522NONO
CVE-2007-1508MEDIUM
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vecto
Mar 20, 20074.322NOYES
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
73%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (33.3%)
Unknown10 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (33.3%)
High0 (0.0%)
Unknown10 (66.7%)
User Interaction
None2 (13.3%)
Unknown10 (66.7%)
Required3 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (33.3%)
Unknown10 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
46.7% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Directadmin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Directadmin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Directadmin's Products

View all 1 CNAs →

Top CWEs