Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zpanel

First CVE: Mar 15, 2005Active for: 21 yearsTotal CVEs: 7

Zpanel is a web-hosting control panel with a narrow product footprint concentrated in the hosting-automation and server-management space. Disclosures affecting the vendor center around the core panel product and reflect the broad attack surface inherent to a web-facing administrative interface; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 79% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zpanel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2005
21 years ago
Most Recent CVE
Aug 4, 2025
354 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2097HIGH
ZPanel through 10.1.0 has Remote Command Execution
Feb 12, 20207.851NOYES
CVE-2013-10053HIGH
A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a
Aug 1, 20258.743NOYES
CVE-2013-10052HIGH
ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be i
Aug 4, 20258.537NOYES
CVE-2005-0792HIGH
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.
Mar 15, 20057.528NOYES
CVE-2007-1123HIGH
Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/temp
Feb 27, 20077.519NONO
CVE-2005-0793HIGH
PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 bet
Mar 15, 20057.519NONO
CVE-2005-0794MEDIUM
ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a d
Mar 15, 20056.417NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
86%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (28.6%)
Network1 (14.3%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None2 (28.6%)
Unknown4 (57.1%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None1 (14.3%)
Unknown4 (57.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
42.9% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zpanel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zpanel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zpanel's Products

View all 3 CNAs →