Vulnerabilities in WebPros
43 resultsVexday analysis
WebPros apresenta 15 vulnerabilidades catalogadas, sendo todas publicadas nos últimos 90 dias, o que indica risco recente e potencialmente em fase de exploração ativa; uma delas está sob ataque confirmado (KEV), com 7 classificadas como críticas. A fraqueza dominante é CWE-94 (execução de código não autorizado), o tipo mais severo para compromisso de integridade de sistemas.
CVE-2026-64639CRITICALIncorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) toEPSS 0.6%CVE-2026-67402CRITICALAn insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual hoEPSS 0.5%CVE-2026-87899CRITICALExecution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.EPSS 0.5%CVE-2026-29203MEDIUMA chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system filEPSS 0.5%CVE-2026-58047MEDIUMHTTP Smuggling in cPanel allows potential leak of credentials.EPSS 0.5%CVE-2026-65642HIGHInsecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and EPSS 0.5%CVE-2026-32999CRITICALInsufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute EPSS 0.5%CVE-2026-67398HIGHMissing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9EPSS 0.5%CVE-2026-64637CRITICALImproper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative sessiEPSS 0.5%CVE-2026-29200CRITICALA critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerabilitEPSS 0.5%CVE-2026-68491CRITICALAn insufficient check allowed for the overwrite of arbitrary files via a symlink.EPSS 0.5%CVE-2026-29204CRITICALInsufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` EPSS 0.5%CVE-2026-64636HIGHAn SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data froEPSS 0.4%CVE-2026-68488CRITICALA Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to rootEPSS 0.4%CVE-2026-29205HIGHIncorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment downloaEPSS 0.4%CVE-2026-32993HIGHImproper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arEPSS 0.4%CVE-2026-29206HIGHInsufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow QueryEPSS 0.4%CVE-2026-68492HIGHAn untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated usersEPSS 0.4%CVE-2026-29201HIGHInsufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relaEPSS 0.3%CVE-2026-32992HIGHSSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and captureEPSS 0.3%