Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-32992 | 1 Cpanel | 3 Cpanel, Whm, Wp Squared | 2026-08-12 | N/A | 8.2 HIGH |
| SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | |||||
| CVE-2026-29205 | 1 Cpanel | 3 Cpanel, Whm, Wp Squared | 2026-08-12 | N/A | 8.6 HIGH |
| Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | |||||
| CVE-2026-41940 | 1 Cpanel | 3 Cpanel, Whm, Wp Squared | 2026-06-17 | N/A | 9.8 CRITICAL |
| cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |||||
