In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
In cPanel before 66.0.2, the cpdavderrorlog file can be created with weak permissions (SEC-280).
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).