Ispconfig

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    3
    Critical Level Threats
    7
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-61518

    ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter

    Last Modified: Aug 21, 2026
    Published: Aug 19, 2026

    CVE-2025-52206

    ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

    Last Modified: May 12, 2026
    Published: May 05, 2026

    CVE-2023-46818

    An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

    Last Modified: Nov 21, 2024
    Published: Oct 27, 2023

    CVE-2021-3021

    ISPConfig before 3.2.2 allows SQL injection.

    Last Modified: Nov 21, 2024
    Published: Jan 05, 2021

    CVE-2020-9398

    ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

    Last Modified: Nov 21, 2024
    Published: Feb 25, 2020
    Items Per Page
    Ispconfig Vulnerabilities & Security CVEs | CVE-DB