Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the getpassword.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.
End of life: 7/8/2025, Latest version: 18.0.69.4
End of life: 5/27/2025, Latest version: 18.0.68.2
End of life: 4/15/2025, Latest version: 18.0.67.3
End of life: 3/4/2025, Latest version: 18.0.66.2
End of life: 3/4/2025, Latest version: 18.0.66.2
End of life: 1/21/2025, Latest version: 18.0.65.2
End of life: 1/21/2025, Latest version: 18.0.65.2
End of life: 12/10/2024, Latest version: 18.0.64.1
End of life: 12/10/2024, Latest version: 18.0.64.1
End of life: 10/29/2024, Latest version: 18.0.63.4
End of life: 10/29/2024, Latest version: 18.0.63.4
End of life: 9/17/2024, Latest version: 18.0.62.2
End of life: 9/17/2024, Latest version: 18.0.62.2
End of life: 8/6/2024, Latest version: 18.0.61.6
End of life: 8/6/2024, Latest version: 18.0.61.6
End of life: 6/25/2024, Latest version: 18.0.60.1
End of life: 6/25/2024, Latest version: 18.0.60.1
End of life: 5/15/2024, Latest version: 18.0.59.2
End of life: 5/15/2024, Latest version: 18.0.59.2
End of life: 4/2/2024, Latest version: 18.0.58.2
End of life: 4/2/2024, Latest version: 18.0.58.2
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
End of life: 2/13/2024, Latest version: 18.0.57.5
End of life: 2/13/2024, Latest version: 18.0.57.5
End of life: 1/2/2024, Latest version: 18.0.56.4
End of life: 1/2/2024, Latest version: 18.0.56.4
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
End of life: 11/21/2023, Latest version: 18.0.55.2
End of life: 11/21/2023, Latest version: 18.0.55.2