Skip to content
Noroxi

Plesk records

12 published records for vendor plesk.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.

    HighCVSS 8.8Proof of conceptEPSS 2%

    plesk · pleskFeb 21, 2022

  • CVE-2023-0829
    36Monitor

    Cross-Site Scripting (XSS) vulnerability in Plesk

    CriticalCVSS 9.0No exploitEPSS 1%

    plesk · pleskSep 20, 2023

  • Plesk 18.0 has Incorrect Access Control.

    CriticalCVSS 9.1No exploitEPSS 1%

    plesk · pleskDec 12, 2025

  • CVE-2023-4931
    31Monitor

    Uncontrolled search path element vulnerability in Plesk

    HighCVSS 7.8No exploitEPSS 0%

    plesk · pleskNov 27, 2023

  • Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component.

    HighCVSS 7.5No exploitEPSS 1%

    plesk · onyxSep 22, 2023

  • Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin

    MediumCVSS 6.5Proof of conceptEPSS 1%

    plesk · pleskFeb 20, 2022

  • Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password.

    MediumCVSS 6.5No exploitEPSS 0%

    plesk · obsidianNov 10, 2022

  • A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites v

    MediumCVSS 6.1Proof of conceptEPSS 2%

    plesk · obsidianJan 21, 2023

  • The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-previe

    MediumCVSS 6.1No exploitEPSS 1%

    plesk · obsidianSep 10, 2021

  • A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML,

    MediumCVSS 6.1No exploitEPSS 1%

    plesk · obsidianAug 3, 2020

  • A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or C

    MediumCVSS 6.1No exploitEPSS 1%

    plesk · onyxAug 3, 2020

  • CVE-2001-1222
    20Monitor

    Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP addres

    MediumCVSS 5.0No exploitEPSS 2%

    plesk · plesk server administratorMar 25, 2002