Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
End of life: 10/27/2026, Latest version: 18.0.80.3
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
End of life: 9/23/2026, Latest version: 18.0.79.7
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.
End of life: 8/4/2026, Latest version: 18.0.78.5
End of life: 6/23/2026, Latest version: 18.0.77.5
End of life: 5/11/2026, Latest version: 18.0.76.6
End of life: 3/31/2026, Latest version: 18.0.75.1
Plesk 18.0 has Incorrect Access Control.
End of life: 2/3/2026, Latest version: 18.0.74.3