Plesk
This hub aggregates every CVE we track for Plesk, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
6
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM8CRITICAL6HIGH5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
1
0
3
2
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Plesk.
- CVE-2026-64637Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.9.9
- CVE-2026-64636An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.7.7
- CVE-2026-58046Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromi...9.9
- CVE-2026-56843Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only fo...9.9
- CVE-2026-48614An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege ...9.9
- CVE-2026-44962Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This a...9.9
- CVE-2025-66430Plesk 18.0 has Incorrect Access Control.9.1
- CVE-2025-66431WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage s...7.8
- CVE-2023-4931Uncontrolled search path element vulnerability in Plesk6.3
- CVE-2023-0829Cross-Site Scripting (XSS) vulnerability in Plesk8.8
- CVE-2021-45008Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem o...8.8
- CVE-2021-45007Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-s...6.5
- CVE-2008-6984Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins...5.8
- CVE-2004-2702Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this migh...4.3
- CVE-2007-4892Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3...7.5
Product normalization is registry-driven with AI assist and human review. How it works