CVE Tools

Cpanel

434 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Cpanel, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Cpanel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cpanel CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-041
2026-058
2026-062
2026-072
2026-080
2026-094

Severity

How the 434 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical235%
  • High11527%
  • Medium23655%
  • Low5613%

Latest CVEs

The 15 most recently published vulnerabilities affecting Cpanel.

  1. CVE-2026-87899Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.—
  2. CVE-2026-68490Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.—
  3. CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component9.9
  4. CVE-2026-65643Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.8.8
  5. CVE-2026-58048Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.—
  6. CVE-2026-58047HTTP Smuggling in cPanel allows potential leak of credentials.—
  7. CVE-2026-9516Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws7.5
  8. CVE-2026-9334Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled7.3
  9. CVE-2026-29206Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.8.1
  10. CVE-2026-32991Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.7.1
  11. CVE-2026-29205Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.8.6
  12. CVE-2026-32993Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.8.3
  13. CVE-2026-32992SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.8.2
  14. CVE-2026-29202Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.8.8
  15. CVE-2026-29201Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.8.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store