Known Vulnerabilities for Obsidian by Plesk
Listed below are 4 of the newest known vulnerabilities associated with "Obsidian" by "Plesk".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42889 json | Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2025-65518 json | Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists... | Not Provided | 2026-01-08 | 2026-07-15 |
| CVE-2023-24044 json | ** DISPUTED ** A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect... | 6.1 - MEDIUM | 2023-01-22 | 2023-11-07 |
| CVE-2022-45130 json | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian ... | 6.5 - MEDIUM | 2022-11-10 | 2022-11-15 |
| CVE-2021-35976 json | The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /pl... | 6.1 - MEDIUM | 2021-09-10 | 2021-11-28 |
| CVE-2020-11583 json | A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary Jav... | 6.1 - MEDIUM | 2020-08-03 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plesk | Obsidian | 18.0.17 |