Directadmin

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-56551

    An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

    Last Modified: Oct 15, 2025
    Published: Oct 03, 2025

    CVE-2019-11193

    The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

    Last Modified: Dec 16, 2025
    Published: Apr 30, 2019

    CVE-2019-9625

    JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019

    CVE-2017-18045

    JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.

    Last Modified: Nov 21, 2024
    Published: Jan 21, 2018

    CVE-2012-5305

    Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.

    Last Modified: Apr 11, 2025
    Published: Oct 06, 2012
    Items Per Page