Known Vulnerabilities for Plesk by Webpros
Listed below are 10 of the newest known vulnerabilities associated with "Plesk" by "Webpros".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65647 json | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-65646 json | Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and ... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-65642 json | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated use... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-64639 json | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (custome... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-64637 json | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an admin... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-64636 json | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arb... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-58046 json | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection a... | Not Provided | 2026-07-30 | 2026-08-14 |
| CVE-2026-56843 json | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer t... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-48614 json | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration d... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-44962 json | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied inpu... | Not Provided | 2026-05-29 | 2026-08-14 |