Known Vulnerabilities for CPanel by Webpros
Listed below are 10 of the newest known vulnerabilities associated with "CPanel" by "Webpros".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87900 json | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary file... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-87899 json | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privile... | Not Provided | 2026-09-23 | 2026-09-24 |
| CVE-2026-87886 json | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for c... | Not Provided | 2026-09-17 | 2026-09-18 |
| CVE-2026-67401 json | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack c... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-65643 json | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | Not Provided | 2026-09-01 | 2026-09-02 |
| CVE-2026-58048 json | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-58047 json | HTTP Smuggling in cPanel allows potential leak of credentials. | Not Provided | 2026-07-31 | 2026-08-07 |
| CVE-2026-56831 json | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-41940 json | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthentica... | Not Provided | 2026-04-29 | 2026-09-30 |
| CVE-2026-14803 json | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-... | Not Provided | 2026-07-06 | 2026-07-06 |