Webhost Automation maintains a narrowly scoped hosting control-panel product line—principally Helm—that serves as a critical administrative interface for web hosting and domain management operations. The vendor's disclosed vulnerabilities cluster around CSRF and related web-application input-handling weaknesses, attack surfaces that are characteristic of administrative panels exposed to network access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webhost Automation over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1499MEDIUM Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject fiel | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2006-1407MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) t | Mar 28, 2006 | 5.8 | 25 | NO | YES |
CVE-2004-1498HIGH SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2006-5984MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txt | Nov 20, 2006 | 6.8 | 18 | NO | NO |
CVE-2007-5251MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or | Oct 6, 2007 | 4.3 | 14 | NO | NO |
CVE-2005-4747MEDIUM Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving th | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webhost Automation.
Media articles that mention a CVE ID that affects a product developed by Webhost Automation — matched by CVE ID, not by vendor name.