Vulnerabilities (CVE)

Filtered by vendor Parallels Subscribe
Filtered by product Parallels Plesk Panel
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4851 2 Microsoft, Parallels 3 Windows 2003 Server, Windows Server 2008, Parallels Plesk Panel 2025-04-11 9.3 HIGH N/A
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.
CVE-2019-18793 1 Parallels 1 Parallels Plesk Panel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.