WHM's vulnerability profile centers on its Autopilot automation product, a narrowly scoped offering for hosting and infrastructure management. Observed disclosures involve classification challenges typical of early-stage or specialized tools where vulnerability details fall outside mainstream weakness taxonomies; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1421HIGH Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to | Dec 31, 2004 | 7.5 | 36 | NO | YES |
CVE-2004-1422MEDIUM WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | Dec 31, 2004 | 5.0 | 31 | NO | YES |
CVE-2004-1420MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sit | Dec 31, 2004 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whm.
Media articles that mention a CVE ID that affects a product developed by Whm — matched by CVE ID, not by vendor name.