Zpanelcp maintains a web-based hosting control panel product that serves small-scale hosting and server administration, with its durable vulnerability signal centered on application-layer input handling and authentication weaknesses including SQL injection, cross-site scripting, cross-site request forgery, hard-coded credentials, and weak password-recovery mechanisms. These flaws reflect the web-application and credential-management complexity inherent to a multi-tenant administrative interface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zpanelcp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5686CRITICAL ZPanel 10.0.1 has insufficient entropy for its password reset process. | Feb 4, 2020 | 9.8 | 43 | NO | YES |
CVE-2012-5685HIGH SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the | Aug 14, 2014 | 7.5 | 34 | NO | YES |
CVE-2012-5683MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) | Aug 14, 2014 | 6.8 | 32 | NO | YES |
CVE-2012-5684MEDIUM Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccoun | Aug 14, 2014 | 4.3 | 27 | NO | YES |
CVE-2012-6654HIGH Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to in | Aug 14, 2014 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zpanelcp.
Media articles that mention a CVE ID that affects a product developed by Zpanelcp — matched by CVE ID, not by vendor name.