c
cPanel
Security Risk Profile
76
/100
highSecurity Risk Score
Comprehensive risk assessment based on 449 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 10, 2003 to present
449
Total CVEs
136
Critical+High
6
Exploited
131
Unpatched
Threat Assessment
Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
131
Critical/High
Risk Level
76/100
high
⚠️ 6 Active Exploits⚡ 3 Zero-Days🆕 1Fresh (<7d)📈 3 in Last 30 Days
Severity Distribution
Critical
41High
95Medium
258Low
43Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
XSS
114
2
Input Validation
72
3
Infoleak
30
4
SQL Injection
10
5
Path Traversal
7
Most Affected Products
1. Cpanel Cpanel1356
2. Cpanel WHM137
3. Cpanel WebHost Manager28
4. Cpanel cPanel & WHM3
5. Cpanel Wp Squared Wordpress3
Recent Vulnerabilities
See more →CVE-2026-87899
CVSS 9.4critical
Sep 23, 2026🔧 No Patch
CVE-2026-67401
CVSS 9.9critical
Sep 9, 2026🔧 No Patch
CVE-2026-65643
CVSS 8.7high
Sep 1, 2026🔧 No Patch
CVE-2026-58047
CVSS 5.6medium
Jul 31, 2026🔧 No Patch
CVE-2026-47365
CVSS 9.9critical
Jun 12, 2026🔧 No Patch
https://reddit.com/r/netsec/comments/1th9bpu/new_age_of_collisions_reading_arbitrary_files/
unknown
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
May 19, 2026🔧 No Patch
CVE-2026-32992
CVSS 8.2high
May 13, 2026🔧 No Patch
CVE-2026-29205
CVSS 8.6high
May 13, 2026
CVE-2026-29203
CVSS 5.3medium
May 8, 2026🔧 No Patch
darkreading-20260504191414
unknown
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
May 4, 2026⚠ Exploited⚡ Zero-Day🔧 No Patch
Monitor cPanel in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.