cPanel before 64.0.21 allows code execution by webmail and demo accounts via a storefilter API call (SEC-236).
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
cPanel before 64.0.21 allows code execution in the context of the root account via a SETVHOSTLANGPACKAGE multilang adminbin call (SEC-237).
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
cPanel before 62.0.4 allows resellers to use the WHM enqueuetransferitem API for queueing non-rearrange modules (SEC-213).
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManagerdimensions API call (SEC-243).
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScannergetsocket API (SEC-251).
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
cPanel before 62.0.4 does not enforce account ownership for hasmycnfforcpuser WHM API calls (SEC-210).
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
cPanel before 62.0.17 allows demo accounts to execute code via an NVDatafetchinc API call (SEC-233).
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).