Vulnerabilities in WebPros
43 resultsVexday analysis
WebPros apresenta 15 vulnerabilidades catalogadas, sendo todas publicadas nos últimos 90 dias, o que indica risco recente e potencialmente em fase de exploração ativa; uma delas está sob ataque confirmado (KEV), com 7 classificadas como críticas. A fraqueza dominante é CWE-94 (execução de código não autorizado), o tipo mais severo para compromisso de integridade de sistemas.
CVE-2026-41940CRITICALWebPros cPanel and WHM Authentication Bypass via Login FlowEPSS 98.5%KEVCVE-2026-65638CRITICALImproper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commaEPSS 2.3%CVE-2026-65639CRITICALOS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured alloEPSS 1.4%CVE-2026-67394CRITICALA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions EPSS 1.3%CVE-2026-87898CRITICALOS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.EPSS 0.9%CVE-2026-65643HIGHEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.EPSS 0.9%CVE-2026-67401CRITICALA vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack componentEPSS 0.9%CVE-2026-67399CRITICALDeserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.EPSS 0.8%CVE-2026-65647HIGHImproper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.EPSS 0.7%CVE-2026-47365CRITICALArgument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass croEPSS 0.7%CVE-2026-65646CRITICALImproper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arEPSS 0.7%CVE-2026-29202MEDIUMInsufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the alEPSS 0.7%CVE-2026-68489HIGHStatic Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to executEPSS 0.7%CVE-2026-56843CRITICALIncorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domaiEPSS 0.7%CVE-2026-68487CRITICALPath traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.EPSS 0.6%CVE-2026-48614CRITICALAn improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resuEPSS 0.6%CVE-2026-58046CRITICALImproper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitraEPSS 0.6%CVE-2026-87900CRITICALArgument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute aEPSS 0.6%CVE-2026-58048CRITICALImproper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.EPSS 0.6%CVE-2026-44962CRITICALPlesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolatEPSS 0.6%