VulnSea

Softaculous has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.1 (high), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
3 prev 0

Products

  • Virtualizor 3
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Softaculous vulnerabilities

CVEs affecting Softaculous, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-43641Critical· 9.8
yesterday

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

MidnightSoftaculous · Virtualizorvia NVD
CVE-2026-43642High· 8.1
yesterday

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

TwilightSoftaculous · Virtualizorvia NVD
CVE-2026-43643High· 7.5
yesterday

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

TwilightSoftaculous · Virtualizorvia NVD
Softaculous vulnerabilities (CVEs) · VulnSea