{"id":"CVE-2025-65518","title":"Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition","summary":"Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-606"],"vendor":"webpros","product":"plesk_obsidian","affected":["plesk_obsidian >= 8.0.1, < 18.0.73"],"patched":["plesk_obsidian 18.0.73"],"published":"2026-01-08","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65518","references":[{"url":"http://plesk.com","label":"cve@mitre.org"},{"url":"https://docs.plesk.com/release-notes/obsidian/change-log/","label":"cve@mitre.org"},{"url":"https://github.com/Jainil-89/CVE-2025-65518/blob/main/cve.md","label":"cve@mitre.org"},{"url":"https://access.redhat.com/security/cve/CVE-2025-65518","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428098","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-65518.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.00621,"epssPercentile":0.48433,"ingestedAt":"2026-06-30T13:26:50.253Z","exploits":{"github":1,"githubRepos":["https://github.com/Jainil-89/CVE-2025-65518"],"checkedAt":"2026-09-23T07:13:43.913Z"},"exploitAvailable":true,"slug":"CVE-2025-65518","body":"## Overview\n\nPlesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.\n\n## Affected\n\n- `plesk_obsidian >= 8.0.1, < 18.0.73`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `plesk_obsidian 18.0.73`","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4895,"id":"CVE-2025-65518","ts":1788887215276,"field":"exploit_available","old":"false","new":"true"},{"seq":3778,"id":"CVE-2025-65518","ts":1788886334828,"field":"exploit_available","old":"true","new":"false"},{"seq":2623,"id":"CVE-2025-65518","ts":1788883013065,"field":"exploit_available","old":"false","new":"true"},{"seq":1652,"id":"CVE-2025-65518","ts":1788882417416,"field":"exploit_available","old":"true","new":"false"},{"seq":760,"id":"CVE-2025-65518","ts":1788881850720,"field":"exploit_available","old":"false","new":"true"}]}