cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
In cPanel before 66.0.2, the cpdavderrorlog file can be created with weak permissions (SEC-280).
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).