WebPros Plesk
7 known vulnerabilities in WebPros Plesk, 4 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-68492 CVSS 8.7 high An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated…
- CVE-2026-68488 CVSS 9.9 critical A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to…
- CVE-2026-68487 CVSS 9.9 critical Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
- CVE-2026-67397 CVSS 8.5 high Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
- CVE-2026-67394 CVSS 9.0 critical A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all…
- CVE-2026-65646 CVSS 9.9 critical Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose…
- CVE-2026-65642 CVSS 8.6 high Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read…