Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in cPanel and WHM

cPanel and WHM contain multiple vulnerabilities that allow unauthenticated or authenticated attackers to perform cross-site scripting (XSS) and execute arbitrary code with administrative privileges.

cPanel and Web Host Manager (WHM) are currently affected by multiple security vulnerabilities. These flaws enable remote attackers to perform cross-site scripting (XSS) attacks or achieve arbitrary code execution within the server environment. Successful exploitation of these vulnerabilities allows an attacker to gain administrative privileges, potentially leading to a full compromise of the cPanel hosting platform. These issues are critical for service providers and system administrators managing Linux-based web hosting infrastructure, as they provide a direct path for escalating access from the web interface to the underlying operating system and management layer.

Impact

Successful exploitation of these vulnerabilities may allow attackers to execute arbitrary commands, steal administrative session tokens, or compromise user data hosted on the server. Given the nature of cPanel/WHM as a central management interface, a successful breach typically results in full system control, potential data exfiltration, and the ability to modify or delete web content across all hosted accounts on the compromised server.

Recommendation

Prioritize reviewing security advisories from the cPanel official documentation portal for the specific patches released to address these vulnerabilities. Monitor web server logs and cPanel access logs for unusual request patterns, particularly those originating from unauthorized sources directed at administrative interfaces or internal API endpoints.


Immediate actions

Review official cPanel security release notes for the latest updates

IT Operations 24h

Mitigations

Apply the latest cPanel/WHM security updates provided by the vendor

immediate IT Operations

Multiple vulnerabilities in cPanel/WHM