CVE security advisories and vulnerability history for cpanel.
cpanel has 431 published CVE records since 2003, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 30 have a known public exploit. The average CVSS base score across scored CVEs is 6.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting cpanel products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on cpanel's vulnerability posture, as a share of its 431 published CVEs.
across 431 scored CVEs
130 of 431 scored
1 of 431 CVEs
30 of 431 CVEs
380 of 431 CVEs
How the CVSS severity of cpanel's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of cpanel's CVEs is confirmed exploited in the wild.
Public exploits
30
30 of cpanel's CVEs have a known public exploit available.
The cpanel products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in cpanel CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish cpanel CVE records.
How many cpanel CVEs were published each year.
The most recently disclosed vulnerabilities affecting cpanel.
Browse vulnerabilities for other tracked vendors.
Common questions about cpanel vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new cpanel vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
Track new cpanel CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor cpanel CVEs