CVE Tools

Webpros

25 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.

Webpros CVEs per month

May 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Webpros CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-05120
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-09130

Products

The products that kept showing up in Webpros's monthly top three, with their CVEs summed over those months.

  1. Cpanel102 months
  2. Wp Squared81 month
  3. Cpanel (Cloudlinux 6, Centos 6)51 month
  4. Plesk41 month
  5. Configserver Security & Firewall31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Webpros.

  1. CVE-2026-87900Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.—
  2. CVE-2026-87898OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.—
  3. CVE-2026-87899Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.—
  4. CVE-2026-68490Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.—
  5. CVE-2026-68492An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful...—
  6. CVE-2026-68491An insufficient check allowed for the overwrite of arbitrary files via a symlink.—
  7. CVE-2026-68489Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.—
  8. CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.—
  9. CVE-2026-65638Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injectio...—
  10. CVE-2026-65639OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to...—
  11. CVE-2026-68488A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.9.9
  12. CVE-2026-68487Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.9.9
  13. CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component9.9
  14. CVE-2026-67402An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is bl...—
  15. CVE-2026-67397Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.—

The record

Peak rank
#94 in Sep 2026
Busiest month shown
Sep 2026, 13 CVEs
Months with a KEV entry
0 since May 2026
Monthly snapshots
2 since 2026
Webpros's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store