CVE-2023-29489: cPanel

Medium severity, CVSS 6.1. EPSS: 65.5% chance of exploitation in the next 30 days.

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

Affected products

  • cPanel cPanel: before 11.102.0.31 (fixed in 11.102.0.31); from 11.104.0, before 11.106.0.18 (fixed in 11.106.0.18); from 11.108.0, before 11.108.0.13 (fixed in 11.108.0.13); from 11.109.0, before 11.109.9999.116 (fixed in 11.109.9999.116)

Published 2023-04-27. Last modified 2026-06-17.