Ehcp is a self-hosted web hosting control panel used for managing hosting infrastructure and account administration. Its vulnerability profile centers on a narrow product scope but has achieved prominence in that niche, with recurring weaknesses centered on input-handling and authentication issues including cross-site scripting, SQL injection, cross-site request forgery, improper authentication, and insufficiently protected credential storage—flaws typical of web-facing administrative interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ehcp over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6361MEDIUM Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. | May 11, 2018 | 6.1 | 40 | NO | NO |
CVE-2018-6458HIGH Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. | May 11, 2018 | 8.8 | 31 | NO | NO |
CVE-2018-6619HIGH Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt. | May 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-6618HIGH Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. | May 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-6617HIGH Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the | May 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2025-50859MEDIUM Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the | Aug 22, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-50858MEDIUM Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript vi | Aug 22, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-50926MEDIUM Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | Aug 19, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-50927MEDIUM A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecti | Aug 8, 2025 | 6.3 | 22 | NO | NO |
CVE-2018-6362MEDIUM Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie. | May 11, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ehcp.
Media articles that mention a CVE ID that affects a product developed by Ehcp — matched by CVE ID, not by vendor name.