CVE-2025-56551: Directadmin

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

Affected products

Published 2025-10-03. Last modified 2026-06-17.