Zpanel is a web-hosting control panel with a narrow product footprint concentrated in the hosting-automation and server-management space. Disclosures affecting the vendor center around the core panel product and reflect the broad attack surface inherent to a web-facing administrative interface; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zpanel over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2097HIGH ZPanel through 10.1.0 has Remote Command Execution | Feb 12, 2020 | 7.8 | 51 | NO | YES |
CVE-2013-10053HIGH A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a | Aug 1, 2025 | 8.7 | 43 | NO | YES |
CVE-2013-10052HIGH ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be i | Aug 4, 2025 | 8.5 | 37 | NO | YES |
CVE-2005-0792HIGH SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php. | Mar 15, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-1123HIGH Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/temp | Feb 27, 2007 | 7.5 | 19 | NO | NO |
CVE-2005-0793HIGH PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 bet | Mar 15, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0794MEDIUM ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a d | Mar 15, 2005 | 6.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zpanel.
Media articles that mention a CVE ID that affects a product developed by Zpanel — matched by CVE ID, not by vendor name.