← Back to CVE List
CVE-2026-93697NVD
Vulnerability Summary
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVSS v3.0 Base Metrics — Score 9.0 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Webpros cPanel < 11.138.0.11
- Webpros cPanel < 11.136.0.45
- Webpros cPanel < 11.134.0.61
- Webpros cPanel < 11.110.0.148
- Webpros WP Squared < 11.138.1.13
- Webpros cPanel 11.138.0.11
- Webpros cPanel 11.136.0.45
- Webpros cPanel 11.134.0.61
- Webpros cPanel 11.110.0.148
- Webpros WP Squared 11.138.1.13
External References
- https://hackerone.com/reports/4047787
- https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026
- https://docs.cpanel.net/changelogs/138-change-log/#138011
- https://docs.cpanel.net/changelogs/136-change-log/#136045
- https://docs.cpanel.net/changelogs/134-change-log/#134061
- https://docs.cpanel.net/changelogs/110-change-log/#1100148
- https://docs.wpsquared.com/changelogs/versions/changelog/#138113