CVE-2026-93029
CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
| CWE | CWE-79 |
| Vendor | webpros |
| Product | cpanel |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for webpros cpanel
Be the first to know when new critical vulnerabilities affecting webpros cpanel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Versions
Webpros / cPanel
0 < 11.138.0.11 0 < 11.136.0.45 0 < 11.134.0.61 0 < 11.110.0.148
Webpros / WP Squared
0 < 11.138.1.13
References
hackerone.com: https://hackerone.com/reports/4047106 support.cpanel.net: https://support.cpanel.net/hc/en-us/articles/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026 docs.cpanel.net: https://docs.cpanel.net/changelogs/138-change-log/#138011 docs.cpanel.net: https://docs.cpanel.net/changelogs/136-change-log/#136045 docs.cpanel.net: https://docs.cpanel.net/changelogs/134-change-log/#134061 docs.cpanel.net: https://docs.cpanel.net/changelogs/110-change-log/#1100148 docs.wpsquared.com: https://docs.wpsquared.com/changelogs/versions/changelog/#138113
Credits
rz1027 (rz1027)