VendorscPanelwhmall versions
Vulnerabilities

cPanel WHM (WebHost Manager)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-41940
WebPros cPanel and WHM Authentication Bypass via Login Flow
Published 2026-04-29 · Analyzed
9.8KEV1 PoCEPSS 0.985
CVE-2026-29205
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Published 2026-05-13 · Analyzed
8.6EPSS 0.004
CVE-2026-32992
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
Published 2026-05-13 · Analyzed
8.2EPSS 0.003
CVE-2012-6449
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
Published 2020-02-10 · Modified
5.4EPSS 0.006
CVE-2017-11441
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
Published 2017-07-19 · Modified
5.4EPSS 0.005