Plesk records
12 published records for vendor plesk.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-281 Improper Preservation of Permissions1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-45008Proof of concept | Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.plesk · plesk · CWE-281 | High8.8 | — | 2.0% | Feb 21, 2022 |
36Monitor | CVE-2023-0829No exploit | Cross-Site Scripting (XSS) vulnerability in Pleskplesk · plesk · CWE-79 | Critical9.0 | — | 0.6% | Sep 20, 2023 |
36Monitor | CVE-2025-66430No exploit | Plesk 18.0 has Incorrect Access Control.plesk · plesk · CWE-284 | Critical9.1 | — | 0.6% | Dec 12, 2025 |
31Monitor | CVE-2023-4931No exploit | Uncontrolled search path element vulnerability in Pleskplesk · plesk · CWE-427 | High7.8 | — | 0.2% | Nov 27, 2023 |
30Monitor | CVE-2023-43784No exploit | Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component.plesk · onyx · CWE-668 | High7.5 | — | 0.6% | Sep 22, 2023 |
26Monitor | CVE-2021-45007Proof of concept | Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin plesk · plesk · CWE-352 | Medium6.5 | — | 0.7% | Feb 20, 2022 |
26Monitor | CVE-2022-45130No exploit | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password.plesk · obsidian · CWE-352 | Medium6.5 | — | 0.4% | Nov 10, 2022 |
25Monitor | CVE-2023-24044Proof of concept | A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites vplesk · obsidian · CWE-601 | Medium6.1 | — | 2.3% | Jan 21, 2023 |
24Monitor | CVE-2021-35976No exploit | The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-previeplesk · obsidian · CWE-79 | Medium6.1 | — | 1.1% | Sep 10, 2021 |
24Monitor | CVE-2020-11583No exploit | A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, plesk · obsidian · CWE-79 | Medium6.1 | — | 1.0% | Aug 3, 2020 |
24Monitor | CVE-2020-11584No exploit | A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or Cplesk · onyx · CWE-79 | Medium6.1 | — | 0.9% | Aug 3, 2020 |
20Monitor | CVE-2001-1222No exploit | Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP addresplesk · plesk server administrator | Medium5.0 | — | 1.6% | Mar 25, 2002 |
- CVE-2021-4500836Monitor
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.
HighCVSS 8.8Proof of conceptEPSS 2%plesk · pleskFeb 21, 2022
- CVE-2023-082936Monitor
Cross-Site Scripting (XSS) vulnerability in Plesk
CriticalCVSS 9.0No exploitEPSS 1%plesk · pleskSep 20, 2023
- CVE-2025-6643036Monitor
Plesk 18.0 has Incorrect Access Control.
CriticalCVSS 9.1No exploitEPSS 1%plesk · pleskDec 12, 2025
- CVE-2023-493131Monitor
Uncontrolled search path element vulnerability in Plesk
HighCVSS 7.8No exploitEPSS 0%plesk · pleskNov 27, 2023
- CVE-2023-4378430Monitor
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component.
HighCVSS 7.5No exploitEPSS 1%plesk · onyxSep 22, 2023
- CVE-2021-4500726Monitor
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin
MediumCVSS 6.5Proof of conceptEPSS 1%plesk · pleskFeb 20, 2022
- CVE-2022-4513026Monitor
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password.
MediumCVSS 6.5No exploitEPSS 0%plesk · obsidianNov 10, 2022
- CVE-2023-2404425Monitor
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites v
MediumCVSS 6.1Proof of conceptEPSS 2%plesk · obsidianJan 21, 2023
- CVE-2021-3597624Monitor
The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-previe
MediumCVSS 6.1No exploitEPSS 1%plesk · obsidianSep 10, 2021
- CVE-2020-1158324Monitor
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML,
MediumCVSS 6.1No exploitEPSS 1%plesk · obsidianAug 3, 2020
- CVE-2020-1158424Monitor
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or C
MediumCVSS 6.1No exploitEPSS 1%plesk · onyxAug 3, 2020
- CVE-2001-122220Monitor
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP addres
MediumCVSS 5.0No exploitEPSS 2%plesk · plesk server administratorMar 25, 2002