Webpros
25 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.
Webpros CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-05 | 12 | 0 |
| 2026-06 | null or fewer | |
| 2026-07 | null or fewer | |
| 2026-08 | null or fewer | |
| 2026-09 | 13 | 0 |
Products
The products that kept showing up in Webpros's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Webpros.
- CVE-2026-87900Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.—
- CVE-2026-87898OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.—
- CVE-2026-87899Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.—
- CVE-2026-68490Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.—
- CVE-2026-68492An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful...—
- CVE-2026-68491An insufficient check allowed for the overwrite of arbitrary files via a symlink.—
- CVE-2026-68489Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.—
- CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.—
- CVE-2026-65638Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injectio...—
- CVE-2026-65639OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to...—
- CVE-2026-68488A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.9.9
- CVE-2026-68487Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.9.9
- CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component9.9
- CVE-2026-67402An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is bl...—
- CVE-2026-67397Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.—
The record
- Peak rank
- #94 in Sep 2026
- Busiest month shown
- Sep 2026, 13 CVEs
- Months with a KEV entry
- 0 since May 2026
- Monthly snapshots
- 2 since 2026