Known Vulnerabilities for CPanel by WebPros
Listed below are 7 of the newest known vulnerabilities associated with "CPanel" by "WebPros".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-58048 json | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-58047 json | HTTP Smuggling in cPanel allows potential leak of credentials. | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-54420 json | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by ... | Not Provided | 2026-06-14 | 2026-06-16 |
| CVE-2026-47365 json | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated user... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-14803 json | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-9516 json | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter call... | Not Provided | 2026-06-03 | 2026-06-03 |
| CVE-2026-9334 json | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is ena... | Not Provided | 2026-06-03 | 2026-06-03 |