Products: 4
    Vulnerabilities: 17
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-66428

    An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.

    Last Modified: Apr 15, 2026
    Published: Jan 22, 2026

    CVE-2025-65518

    plesk: Plesk Obsidian: Denial of Service via crafted request to get_password.php

    Last Modified: Jan 30, 2026
    Published: Jan 08, 2026

    CVE-2025-66430

    Plesk 18.0 has Incorrect Access Control.

    Last Modified: Jan 06, 2026
    Published: Dec 12, 2025

    CVE-2025-66431

    WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."

    Last Modified: Apr 15, 2026
    Published: Dec 03, 2025

    CVE-2025-54336

    In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

    Last Modified: Apr 15, 2026
    Published: Aug 19, 2025
    Items Per Page
    Plesk Vulnerabilities & Security CVEs | CVE-DB