Plesk 在 18.0.34 至 18.0.80.8 之前版本以及 18.0.81 至 18.0.81.1 之前版本中存在一个不受信任的搜索路径漏洞。远程已认证用户可通过 2.4.2 至 2.4.7 之前的“Plesk RESTful API”扩展,利用该漏洞以 root 权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebPros | Plesk | 18.0.34 ~ 18.0.80.8 | - |
|
| WebPros | Plesk extension "Plesk RESTful API" | 2.4.2 ~ 2.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87900 | 9.4 CRITICAL | cPanel 6.11.2-10794 WP Toolkit参数注入漏洞 |
| CVE-2026-87899 | 9.4 CRITICAL | cPanel提权漏洞:远程用户可获Root权限执行代码 |
| CVE-2026-87898 | 9.4 CRITICAL | Plesk远程认证命令注入漏洞 |
| CVE-2026-68490 | 8.2 HIGH | Thunderbird 权限配置错误致敏感信息泄露 |
No comments yet