Stored XSS Vulnerability in WHM Mass Modify Accounts Interface by cPanel
CVE-2026-93697
9CRITICAL
What is CVE-2026-93697?
A stored cross-site scripting (XSS) vulnerability exists in the WHM Mass Modify Accounts interface, which allows malicious actors to execute arbitrary code. This vulnerability can be exploited by injecting harmful scripts into user inputs that are stored in the system, potentially compromising user accounts and sensitive information. It is critical to address this vulnerability promptly to protect against unauthorized access and data breaches. Patching and securing affected versions is recommended for enhanced security.
Affected Version(s)
cPanel 0 < 11.138.0.11
cPanel 0 < 11.136.0.45
cPanel 0 < 11.134.0.61
