CVE-2026-93029: CWE-79 Cross-site Scripting (XSS) - Stored in Webpros cPanel
CVE-2026-93029 is a critical stored cross-site scripting (XSS) vulnerability in Webpros cPanel affecting the WHM Manage SSL Hosts interface. This flaw allows an attacker with limited privileges to execute arbitrary code via stored malicious scripts. The vulnerability impacts multiple versions of cPanel prior to specific fixed releases.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-93029) is a stored cross-site scripting (CWE-79) issue in the Webpros cPanel product, specifically within the WHM Manage SSL Hosts interface. It allows an attacker with low privileges to inject and execute arbitrary code in the context of the affected application. The CVSS v3.0 score is 9.0, indicating critical severity with network attack vector, low attack complexity, requiring privileges, user interaction, and resulting in complete confidentiality, integrity, and availability impact. Multiple versions of cPanel prior to 11.138.0.11, 11.136.0.45, 11.134.0.61, 11.110.0.148, and 11.138.1.13 are affected.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code within the cPanel environment, potentially leading to full compromise of confidentiality, integrity, and availability of the system. This can result in unauthorized access, data theft, or disruption of services.
Mitigation Recommendations
No explicit patch links or vendor advisory content are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, restrict access to the WHM Manage SSL Hosts interface to trusted administrators only and monitor for suspicious activity.
CVE-2026-93029: CWE-79 Cross-site Scripting (XSS) - Stored in Webpros cPanel
Description
CVE-2026-93029 is a critical stored cross-site scripting (XSS) vulnerability in Webpros cPanel affecting the WHM Manage SSL Hosts interface. This flaw allows an attacker with limited privileges to execute arbitrary code via stored malicious scripts. The vulnerability impacts multiple versions of cPanel prior to specific fixed releases.
CVSS v3.0
Score 9.0critical
Affected software
Webpros
cPanel
Webpros
WP Squared
pkg:github/webpros/cpanelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-93029) is a stored cross-site scripting (CWE-79) issue in the Webpros cPanel product, specifically within the WHM Manage SSL Hosts interface. It allows an attacker with low privileges to inject and execute arbitrary code in the context of the affected application. The CVSS v3.0 score is 9.0, indicating critical severity with network attack vector, low attack complexity, requiring privileges, user interaction, and resulting in complete confidentiality, integrity, and availability impact. Multiple versions of cPanel prior to 11.138.0.11, 11.136.0.45, 11.134.0.61, 11.110.0.148, and 11.138.1.13 are affected.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code within the cPanel environment, potentially leading to full compromise of confidentiality, integrity, and availability of the system. This can result in unauthorized access, data theft, or disruption of services.
Mitigation Recommendations
No explicit patch links or vendor advisory content are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, restrict access to the WHM Manage SSL Hosts interface to trusted administrators only and monitor for suspicious activity.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2026-09-17T15:00:00.689Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6abf535aa43b0b3b8981aeb7
Added to database: 10/02/2026, 06:46:50 UTC
Last enriched: 10/02/2026, 07:01:20 UTC
Last updated: 10/02/2026, 12:31:43 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.