Ispconfig is a modestly represented hosting control panel and server management platform that, despite a narrow product scope, occupies a prominent position among administrative interfaces in shared hosting and multi-tenant server environments. Its vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency toward public exploit availability, reflecting the high value of administrative access and the web-application attack surface inherent to panel software. The exposure recurs through injection and cross-site flaws—SQL injection, code injection, cross-site scripting, and cross-site request forgery—that are characteristic of older server-management interfaces and remain durable targets for both remote compromise and privilege escalation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ispconfig over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3629HIGH ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution | Feb 7, 2020 | 8.8 | 64 | NO | YES |
CVE-2023-46818HIGH An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. | Oct 27, 2023 | 7.2 | 50 | NO | YES |
CVE-2006-2315HIGH PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][cla | May 12, 2006 | 7.5 | 30 | NO | YES |
CVE-2021-3021CRITICAL ISPConfig before 3.2.2 allows SQL injection. | Jan 5, 2021 | 9.8 | 29 | NO | NO |
CVE-2012-2087CRITICAL ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface. | Jan 23, 2020 | 9.8 | 29 | NO | NO |
CVE-2006-3042HIGH Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter | Jun 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2020-9398CRITICAL ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection. | Feb 25, 2020 | 9.8 | 28 | NO | NO |
CVE-2018-17984HIGH An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated | Oct 4, 2018 | 7.8 | 27 | NO | NO |
CVE-2017-17384HIGH ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. | Dec 7, 2017 | 8.8 | 27 | NO | NO |
CVE-2015-4119MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that | Jun 15, 2015 | 6.8 | 26 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ispconfig.
Media articles that mention a CVE ID that affects a product developed by Ispconfig — matched by CVE ID, not by vendor name.