Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-66430 Plesk 18.0 has Incorrect Access Control. Plesk 18.0.73.5 / 18.0.74.2+ Fix from $2,3002025-12-12 HIGH 7.8 CVE-2023-4931 Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injectin… Plesk Mitigation only Fix from $1,9502023-11-27 HIGH 7.5 CVE-2023-43784 Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is th… Onyx No fix yet Fix from $1,9502023-09-22 CRITICAL 9.0 CVE-2023-0829 Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user)… Plesk after 18.0.31 Fix from $2,3002023-09-20 MEDIUM 6.1 CVE-2023-24044 A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host… Obsidian after 18.0.49 Fix from $1,6002023-01-22 MEDIUM 6.5 CVE-2022-45130 Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of… Obsidian No fix yet Fix from $1,6002022-11-10 HIGH 8.8 CVE-2021-45008 Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor st… Plesk No fix yet Fix from $1,9502022-02-21 MEDIUM 6.5 CVE-2021-45007 Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NO… Plesk No fix yet Fix from $1,6002022-02-20 MEDIUM 6.1 CVE-2021-35976 The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, … Obsidian after 18.0.32 Fix from $1,6002021-09-10 MEDIUM 6.1 CVE-2020-11583 A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS vi… Obsidian Mitigation only Fix from $1,6002020-08-03 MEDIUM 6.1 CVE-2020-11584 A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a … Onyx Mitigation only Fix from $1,6002020-08-03 MEDIUM 5.0 CVE-2001-1222 Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a v… Plesk Server Administrator Patch available Fix from $1,6002002-03-25