Exposição de Plesk
Hosting panels133
score de exposição
270.029
sites usam
0
em exploração
10
críticos
CVEs
15 resultadosCVE-2026-67394CRITICALA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions EPSS 1.3%CVE-2026-44962CRITICALPlesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolatEPSS 0.7%CVE-2026-56843CRITICALIncorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domaiEPSS 0.7%CVE-2023-0829HIGHCross-Site Scripting (XSS) vulnerability in PleskEPSS 0.6%CVE-2026-48614CRITICALAn improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resuEPSS 0.6%CVE-2026-65642HIGHInsecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and EPSS 0.5%CVE-2026-68487CRITICALPath traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.EPSS 0.4%CVE-2026-65646CRITICALImproper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arEPSS 0.4%CVE-2026-58046CRITICALImproper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitraEPSS 0.4%CVE-2026-64639CRITICALIncorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) toEPSS 0.3%CVE-2026-64637CRITICALImproper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative sessiEPSS 0.3%CVE-2026-64636HIGHAn SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data froEPSS 0.3%CVE-2025-66431HIGHWebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root viaEPSS 0.3%CVE-2026-68488CRITICALA Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to rootEPSS 0.2%CVE-2026-67397HIGHPath traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.EPSS 0.1%