CVE-2016-10816: cPanel
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
Affected products
- cPanel cPanel: from 11.50.0.4, before 11.50.6.2 (fixed in 11.50.6.2); from 11.52.6.0, before 11.52.6.1 (fixed in 11.52.6.1); from 11.54.0.0, before 11.54.0.24 (fixed in 11.54.0.24); from 56.0.1, before 56.0.15 (fixed in 56.0.15)
Published 2019-08-01. Last modified 2026-06-17.