CVE-2025-52206
- EPSS 0.22%
- Veröffentlicht 05.05.2026 16:16:09
- Zuletzt bearbeitet 12.05.2026 15:54:14
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2023-46818
- EPSS 13.89%
- Veröffentlicht 27.10.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 08:29:22
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
CVE-2021-3021
- EPSS 2.12%
- Veröffentlicht 05.01.2021 16:15:15
- Zuletzt bearbeitet 21.11.2024 06:20:46
ISPConfig before 3.2.2 allows SQL injection.
CVE-2020-9398
- EPSS 1.27%
- Veröffentlicht 25.02.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:33
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2013-3629
- EPSS 43.1%
- Veröffentlicht 07.02.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:01
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
CVE-2012-2087
- EPSS 2.71%
- Veröffentlicht 23.01.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:38:27
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
CVE-2018-17984
- EPSS 3.37%
- Veröffentlicht 04.10.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:19
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
- EPSS 1.49%
- Veröffentlicht 07.12.2017 08:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
CVE-2015-4119
- EPSS 1.26%
- Veröffentlicht 15.06.2015 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php...
CVE-2015-4118
- EPSS 2.14%
- Veröffentlicht 15.06.2015 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote atta...