Known Vulnerabilities for Plesk by Swsoft
Listed below are 6 of the newest known vulnerabilities associated with "Plesk" by "Swsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68488 json | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege esc... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-68487 json | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-67397 json | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as r... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-67394 json | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affectin... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-65647 json | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | Not Provided | 2026-08-26 | 2026-08-27 |
| CVE-2026-65646 json | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users... | Not Provided | 2026-08-26 | 2026-09-11 |
| CVE-2026-65642 json | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated use... | Not Provided | 2026-08-26 | 2026-08-27 |
| CVE-2026-64639 json | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (custome... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-64637 json | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an admin... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-64636 json | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arb... | Not Provided | 2026-08-07 | 2026-08-07 |