VulnSea

WebPros has 11 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 9.4 (critical), with 8 rated critical. None have a confirmed exploitation report. Most affected products: Plesk (3), ConfigServer Security & Firewall (2), WHMCS (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.4
Publish → KEV
Last 90 days
10 prev 0

Products

  • Plesk 3
  • ConfigServer Security & Firewall 2
  • WHMCS 2
  • Plesk extension "Ruby" 1
  • SolusVM 1
  • cPanel 1
11
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

WebPros vulnerabilities

CVEs affecting WebPros, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-68491Critical· 9.4
1w ago

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

MidnightWebpros · SolusVMEPSS 0.33%via NVD
CVE-2026-68489High· 8.7
1w ago

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

TwilightWebPros · Plesk extension "Ruby"EPSS 0.40%via NVD
CVE-2026-67399Critical· 9.3
1w ago

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

MidnightWebPros · WHMCSEPSS 0.69%via NVD
CVE-2026-68488Critical· 9.9
1w ago

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

MidnightWebPros · PleskEPSS 0.23%via NVD
CVE-2026-65639Critical· 9.5
1w ago

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

MidnightWebPros · ConfigServer Security & FirewallEPSS 1.6%via CVEORG
CVE-2026-65638Critical· 9.2
1w ago

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

MidnightWebPros · ConfigServer Security & FirewallEPSS 3.2%via CVEORG
CVE-2026-68487Critical· 9.9
1w ago

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

MidnightWebPros · PleskEPSS 0.41%via CVEORG
CVE-2026-67401Critical· 9.9PoC
1w ago

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

AbyssalWebPros · cPanelEPSS 1.0%via NVD
CVE-2026-67398High· 8.2
2w ago

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get …

TwilightWebPros · WHMCSEPSS 0.28%via NVD
CVE-2026-65646Critical· 9.9
3w ago

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

MidnightWebPros · PleskEPSS 0.39%via CVEORG
CVE-2025-65518High· 7.5PoC
8mo ago

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…

Midnightwebpros · plesk_obsidianEPSS 0.62%via NVD
WebPros vulnerabilities (CVEs) · VulnSea