WebPros has 11 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 9.4 (critical), with 8 rated critical. None have a confirmed exploitation report. Most affected products: Plesk (3), ConfigServer Security & Firewall (2), WHMCS (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.4
- Publish → KEV
- —
- Last 90 days
- 10 prev 0
Products
- Plesk 3
- ConfigServer Security & Firewall 2
- WHMCS 2
- Plesk extension "Ruby" 1
- SolusVM 1
- cPanel 1
Worst active — by depth score
CVE-2026-67401Critical· 9.9A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component67CVE-2026-68487Critical· 9.9Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.55CVE-2026-65646Critical· 9.9Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.55CVE-2026-68488Critical· 9.9A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.54CVE-2026-65639Critical· 9.5OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…53
WebPros vulnerabilities
CVEs affecting WebPros, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-68491Critical· 9.4An insufficient check allowed for the overwrite of arbitrary files via a symlink.
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
CVE-2026-68489High· 8.7Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
CVE-2026-67399Critical· 9.3Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
CVE-2026-68488Critical· 9.9A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
CVE-2026-65639Critical· 9.5OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…
CVE-2026-65638Critical· 9.2Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…
CVE-2026-68487Critical· 9.9Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
CVE-2026-67401Critical· 9.9PoCA vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
CVE-2026-67398High· 8.2Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get …
CVE-2026-65646Critical· 9.9Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
CVE-2025-65518High· 7.5PoCPlesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…