VENDOR

WebPros vulnerabilities: CVEs, exploitation and patches

Every WebPros CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-65647
    Plesk Migrator symlink flaw allows authenticated users to run code as root WebPros Plesk Migrator ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.7
  2. CVE-2026-65643
    CPanel eval injection authenticated code execution as root WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  3. CVE-2026-58048
    CPanel SQL injection lets low-privilege users run SQL as root WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.4
  4. CVE-2026-67401
    CPanel EmailTrack SQL injection remote code execution WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.9
4 CVEs · page 1 of 1