CVE-2026-93029: Stored XSS in the cPanel-WHM interface

This text was generated using artificial intelligence (AI).The NVD lists CVE-2026-93029 since October 2, 2026 as a stored XSS vulnerability in the WHM interface Manage SSL Hosts by WebPros cPanel. The CVSS score is 9.0.

WebPros cPanel has repeatedly drawn attention in recent months due to critical security findings. According to SecurityAffairs, CVE-2026-41940, an authentication bypass in cPanel and WHM with a CVSS score of 9.8, was recorded in the Known Exploited Vulnerabilities catalog as actively exploited by CISA in April 2026. In August 2026, a report on CVE-2026-58048 followed, a vulnerability that allowed authenticated users to execute SQL commands with root privileges. The accumulation of critical findings in WebPros products underscores the importance of continuous vendor risk monitoring for operators of cPanel and WHM installations.

Are my systems affected? Check now →