CVE Tools

Plesk

27 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Plesk, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Plesk CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Plesk CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-010
2026-020
2026-030
2026-040
2026-051
2026-060
2026-073
2026-085
2026-095

Severity

How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical941%
  • High523%
  • Medium836%

Latest CVEs

The 15 most recently published vulnerabilities affecting Plesk.

  1. CVE-2026-68492An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful...—
  2. CVE-2026-68488A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.9.9
  3. CVE-2026-68487Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.9.9
  4. CVE-2026-67397Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.—
  5. CVE-2026-67394A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerab...—
  6. CVE-2026-65642Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.—
  7. CVE-2026-65646Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.9.9
  8. CVE-2026-64639Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server ...—
  9. CVE-2026-64637Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.9.9
  10. CVE-2026-64636An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.7.7
  11. CVE-2026-58046Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromi...9.9
  12. CVE-2026-56843Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only fo...9.9
  13. CVE-2026-48614An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege ...9.9
  14. CVE-2026-44962Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This a...9.9
  15. CVE-2025-66430Plesk 18.0 has Incorrect Access Control.9.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store