Stored XSS Vulnerability in WHM Mass Modify Accounts Interface by cPanel
CVE-2026-93697

9CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
2 October 2026

What is CVE-2026-93697?

A stored cross-site scripting (XSS) vulnerability exists in the WHM Mass Modify Accounts interface, which allows malicious actors to execute arbitrary code. This vulnerability can be exploited by injecting harmful scripts into user inputs that are stored in the system, potentially compromising user accounts and sensitive information. It is critical to address this vulnerability promptly to protect against unauthorized access and data breaches. Patching and securing affected versions is recommended for enhanced security.

Affected Version(s)

cPanel 0 < 11.138.0.11

cPanel 0 < 11.136.0.45

cPanel 0 < 11.134.0.61

References

CVSS V3.0

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027 (rz1027)
.