{"id":99173,"date":"2026-10-02T14:31:42","date_gmt":"2026-10-02T12:31:42","guid":{"rendered":"https:\/\/locaterisk.com\/de\/?p=99173"},"modified":"2026-10-02T14:31:42","modified_gmt":"2026-10-02T12:31:42","slug":"cpanel-whm-stored-xss-cve-2026-93029","status":"publish","type":"post","link":"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/","title":{"rendered":"CVE-2026-93029: Stored XSS in the cPanel-WHM interface"},"content":{"rendered":"\n<div class=\"wp-block-lr-blog-article-header-module\">\n    <div class=\"content\">\n\t\t<div class=\"headline\">\n\t\t\t<a class=\"to-blog-button\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">\n\t\t\t\t<span class=\"to-blog-arrow\" aria-hidden=\"true\">\u2190<\/span>\n\t\t\t\t<span>Back to blog<\/span>\n\t\t\t<\/a>\n\t\t\t<div class=\"article-meta\">\n\t\t\t\t\t\t\t\t\t<p class=\"post-updated\">Published: October 2, 2026<\/p>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n        <div class=\"main-content\">\n\t\t\t<h1 class=\"title\">CVE-2026-93029: Stored XSS im cPanel-WHM-Interface<\/h1>\n\t\t\t\t\t\t\t<p class=\"paragraph\"><span class=\"lr-ai-disclosure\" style=\"display:block;margin:8px 0 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic\">Dieser Text wurde mit k\u00fcnstlicher Intelligenz (KI) erstellt.<\/span>Die NVD f\u00fchrt <strong>CVE-2026-93029<\/strong> seit dem 2. Oktober 2026 als Stored-XSS-Schwachstelle in der WHM-Oberfl\u00e4che <strong>Manage SSL Hosts<\/strong> von WebPros cPanel. Der CVSS-Score betr\u00e4gt <strong>9.0<\/strong>.<br><br>WebPros cPanel ist in den vergangenen Monaten wiederholt durch kritische Sicherheitsbefunde aufgefallen. Laut SecurityAffairs wurde CVE-2026-41940, ein Authentication-Bypass in cPanel und WHM mit einem CVSS-Score von 9.8, im April 2026 von der CISA als aktiv ausgenutzt in den Known-Exploited-Vulnerabilities-Katalog aufgenommen. Im August 2026 folgte die Meldung zu CVE-2026-58048, einer Schwachstelle, die authentifizierten Nutzern die Ausf\u00fchrung von SQL-Befehlen mit Root-Rechten erm\u00f6glichte. Die H\u00e4ufung kritischer Befunde bei WebPros-Produkten unterstreicht die Bedeutung eines kontinuierlichen Vendor-Risk-Monitorings f\u00fcr Betreiber von cPanel- und WHM-Installationen.<br><br><a href=\"#cve-check\" class=\"lr-cveqc-jump\" style=\"display:inline-block;font-weight:700;color:#26d9c3;text-decoration:none\">Sind meine Systeme betroffen? Jetzt pr\u00fcfen \u2192<\/a><\/p>\n\t\t\t        <\/div>\n    <\/div>\n<\/div>\n\n\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" alt=\"CVE-2026-93029: Stored XSS im cPanel-WHM-Interface\" class=\"wp-image-9138\" srcset=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png 400w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-300x300.png 300w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-150x150.png 150w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-12x12.png 12w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Auf einen Blick:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Schwachstelle: <strong>CVE-2026-93029<\/strong> (<strong>CVSS 9.0<\/strong>, kritisch)<\/li>\n\n\n\n<li>Status: kein aktiver Missbrauch belegt<\/li>\n\n\n\n<li>Patch verf\u00fcgbar seit: 29.09.2026<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Die Schwachstelle im \u00dcberblick<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-ID:<\/strong> CVE-2026-93029<\/li>\n\n\n\n<li><strong>Betroffenes Produkt:<\/strong> WebPros cPanel<\/li>\n\n\n\n<li><strong>Betroffene Oberfl\u00e4che:<\/strong> WHM Manage SSL Hosts<\/li>\n\n\n\n<li><strong>Schwachstellentyp:<\/strong> Stored Cross-Site Scripting, <strong>CWE-79<\/strong><\/li>\n\n\n\n<li><strong>CVSS-Score:<\/strong> 9.0<\/li>\n\n\n\n<li><strong>CVSS-Vektor:<\/strong> CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:H\/I:H\/A:H<\/li>\n\n\n\n<li><strong>Voraussetzungen:<\/strong> niedrige Berechtigungen und Nutzerinteraktion<\/li>\n\n\n\n<li><strong>Patchstatus:<\/strong> behoben in cPanel <strong>11.138.0.11<\/strong>, <strong>11.136.0.45<\/strong>, <strong>11.134.0.61<\/strong> und <strong>11.110.0.148<\/strong> (LTS) sowie WP Squared <strong>11.138.1.13<\/strong> (cPanel-Advisory vom 29. September 2026)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Technische Einordnung<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Laut NVD erm\u00f6glicht die Stored-XSS-Schwachstelle in der WHM-Oberfl\u00e4che Manage SSL Hosts die Ausf\u00fchrung beliebigen Codes. Die Bewertung beschreibt einen netzwerkbasierten Angriff, f\u00fcr den niedrige Berechtigungen und eine Nutzerinteraktion erforderlich sind.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Der ver\u00f6ffentlichte CVSS-Eintrag weist zudem einen Scope-Wechsel sowie hohe Auswirkungen auf Vertraulichkeit, Integrit\u00e4t und Verf\u00fcgbarkeit aus. Diese Angaben unterst\u00fctzen eine priorisierte technische Pr\u00fcfung der eingesetzten cPanel- und WHM-Instanzen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Patchstatus und Priorisierung<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">cPanel hat CVE-2026-93029 mit dem Sicherheitsrelease vom <strong>29. September 2026<\/strong> behoben. Die Korrektur steckt in cPanel <strong>11.138.0.11<\/strong>, <strong>11.136.0.45<\/strong>, <strong>11.134.0.61<\/strong> und <strong>11.110.0.148<\/strong> (LTS) sowie WP Squared <strong>11.138.1.13<\/strong>. Betroffen sind die Builds unterhalb dieser St\u00e4nde.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Empfohlene Schritte:<\/p>\n\n\n\n<ol class=\"wp-block-list has-text-color\" style=\"color:#ffffff\">\n<li>Installierten Branch und Build je cPanel- und WP-Squared-Instanz feststellen.<\/li>\n\n\n\n<li>Instanzen unterhalb der genannten Builds priorisiert aktualisieren.<\/li>\n\n\n\n<li>Konten mit Zugriff auf die WHM-Oberfl\u00e4che Manage SSL Hosts pr\u00fcfen, da die Ausnutzung niedrige Berechtigungen voraussetzt.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Die CVSS-Bewertung ersetzt keine Pr\u00fcfung der jeweiligen Umgebung. F\u00fcr die Einordnung sind insbesondere die vorhandenen Berechtigungen, die erforderliche Nutzerinteraktion sowie der Patchstatus der betroffenen cPanel- und WHM-Installationen relevant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">cPanel und WHM werden von zahlreichen deutschen und \u00f6sterreichischen Hosting-Anbietern eingesetzt. Gelingt die Ausnutzung dieser Schwachstelle und sind dabei personenbezogene Daten betroffen, kann dies unter der DSGVO eine Meldepflicht gegen\u00fcber der zust\u00e4ndigen Datenschutzbeh\u00f6rde innerhalb von 72 Stunden ausl\u00f6sen (Art. 33 DSGVO). NIS-2-pflichtige Hosting-Provider in Deutschland sowie Anbieter, die dem \u00f6sterreichischen NISG unterliegen, sollten die Verwundbarkeit ihrer Infrastruktur gezielt pr\u00fcfen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>LocateRisk: Sichtbarkeit f\u00fcr \u00f6ffentlich erreichbare cPanel- und WHM-Systeme<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">cPanel- und WHM-Installationen k\u00f6nnen unter Kundendomains betrieben und extern identifiziert werden. LocateRisk unterst\u00fctzt im EASM-Kontext dabei, \u00f6ffentlich erreichbare Systeme und eingesetzte Software sichtbar zu machen. Dadurch l\u00e4sst sich pr\u00fcfen, wo cPanel- oder WHM-Instanzen unter eigenen Domains erreichbar sind \u2014 einschlie\u00dflich vergessener Subdomains oder nicht zentral erfasster Cloud-Assets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Die Sichtbarkeit eines Systems belegt nicht automatisch die konkrete Verwundbarkeit einer Instanz. Die Bewertung von CVE-2026-93029 erfordert weiterhin eine Pr\u00fcfung von Patchstatus und Konfiguration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Erg\u00e4nzend kann LocateRisk C-VRM Hinweise erfassen, wenn bei Anbietern wie WebPros kritische Schwachstellen bekannt werden oder sich deren Sicherheitsniveau ver\u00e4ndert \u2014 wie die j\u00fcngste H\u00e4ufung kritischer CVEs bei cPanel zeigt. F\u00fcr diese CVE verbindet die Sichtbarkeit eigener \u00f6ffentlich erreichbarer Systeme mit der Pr\u00fcfung von Herstellerinformationen zwei getrennte Aufgaben: die Erfassung potenziell betroffener Infrastruktur und die organisatorische Priorisierung der Pr\u00fcfung.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Bin ich betroffen?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Betroffen sind cPanel\/WHM und WP Squared in den oben genannten Versionen; behoben ist die Schwachstelle ab den genannten Builds. Wer wissen will, ob cPanel\/WHM oder WP Squared in der eigenen extern erreichbaren Infrastruktur \u00fcberhaupt sichtbar sind, kann den <a href=\"#cve-check\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-Quick-Check<\/a> am Ende dieses Artikels nutzen: Er zeigt exponierte Systeme und die von au\u00dfen erkennbare Software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Die konkret installierte Version l\u00e4sst sich von au\u00dfen nicht in jedem Fall bestimmen \u2014 ausschlaggebend ist der Abgleich mit dem Hersteller-Advisory.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Quellen und weitere Infos<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>cPanel (WebPros):<\/strong> <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026\" target=\"_blank\" rel=\"noreferrer noopener\">Security: CVE-2026-93029 \u2013 Stored XSS in WHM&#8217;s Manage SSL Hosts Interface<\/a><\/li>\n\n\n\n<li><strong>NVD \/ NIST:<\/strong> <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-93029\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-93029<\/a><\/li>\n\n\n\n<li><strong>Threat Radar:<\/strong> <a href=\"https:\/\/radar.offseq.com\/threat\/cve-2026-93029-cwe-79-cross-site-scripting-xss-stored-in-webpros-cpanel-7c14cb89e30db301\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-93029 \u2013 CWE-79 Stored XSS in WebPros cPanel<\/a><\/li>\n\n\n\n<li><strong>SecurityAffairs:<\/strong> <a href=\"https:\/\/securityaffairs.com\/191613\/hacking\/u-s-cisa-adds-a-flaw-in-webpros-cpanel-to-its-known-exploited-vulnerabilities\" target=\"_blank\" rel=\"noreferrer noopener\">CISA adds CVE-2026-41940 (WebPros cPanel) to Known Exploited Vulnerabilities catalog<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3><strong>H\u00e4ufige Fragen<\/strong><\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Was ist CVE-2026-93029?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">CVE-2026-93029 ist eine Stored-XSS-Schwachstelle (CWE-79) in der WHM-Oberfl\u00e4che Manage SSL Hosts von WebPros cPanel. Sie erm\u00f6glicht laut NVD die Ausf\u00fchrung beliebigen Codes und wurde am 2. Oktober 2026 ver\u00f6ffentlicht. Der CVSS-Score betr\u00e4gt 9.0.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Welche Systeme sind betroffen?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Betroffen sind Installationen von WebPros cPanel, die das WHM-Interface Manage SSL Hosts nutzen. Ein Angriff setzt eine Netzwerkverbindung, niedrige Berechtigungen und eine Nutzerinteraktion voraus. Betroffen sind cPanel-Builds unterhalb von 11.138.0.11, 11.136.0.45, 11.134.0.61 und 11.110.0.148 sowie WP Squared unterhalb von 11.138.1.13.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Gibt es bereits einen Patch?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Ja. cPanel hat die Schwachstelle am 29. September 2026 behoben. Die korrigierten Builds sind 11.138.0.11, 11.136.0.45, 11.134.0.61 und 11.110.0.148; f\u00fcr WP Squared ist es Build 11.138.1.13.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"@id\":\"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#faq\",\"url\":\"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/\"},\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Was ist CVE-2026-93029?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-93029 ist eine Stored-XSS-Schwachstelle (CWE-79) in der WHM-Oberfl\u00e4che Manage SSL Hosts von WebPros cPanel. Sie erm\u00f6glicht laut NVD die Ausf\u00fchrung beliebigen Codes und wurde am 2. Oktober 2026 ver\u00f6ffentlicht. Der CVSS-Score betr\u00e4gt 9.0.\"}},{\"@type\":\"Question\",\"name\":\"Welche Systeme sind betroffen?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Betroffen sind Installationen von WebPros cPanel, die das WHM-Interface Manage SSL Hosts nutzen. Ein Angriff setzt eine Netzwerkverbindung, niedrige Berechtigungen und eine Nutzerinteraktion voraus. Betroffen sind cPanel-Builds unterhalb von 11.138.0.11, 11.136.0.45, 11.134.0.61 und 11.110.0.148 sowie WP Squared unterhalb von 11.138.1.13.\"}},{\"@type\":\"Question\",\"name\":\"Gibt es bereits einen Patch?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Ja. cPanel hat die Schwachstelle am 29. September 2026 behoben. Die korrigierten Builds sind 11.138.0.11, 11.136.0.45, 11.134.0.61 und 11.110.0.148; f\u00fcr WP Squared ist es Build 11.138.1.13.\"}}]}<\/script>\n\n\n<p class=\"lr-legal-note\" style=\"margin:32px 0 0;padding-top:16px;border-top:1px solid #e5e7eb;font-size:13px;line-height:1.55;color:#8b93a7;font-style:italic;\">Stand: 02.10.2026. Dieser Beitrag dient allgemeinen Informationszwecken und ist keine Rechts-, Sicherheits- oder Handlungsberatung im Einzelfall. Sicherheitslage und Patch-Verf\u00fcgbarkeit k\u00f6nnen sich seit der Ver\u00f6ffentlichung ge\u00e4ndert haben; ma\u00dfgeblich ist stets das verlinkte Hersteller-Advisory. Trotz sorgf\u00e4ltiger Recherche \u00fcbernehmen wir keine Gew\u00e4hr f\u00fcr Aktualit\u00e4t, Richtigkeit und Vollst\u00e4ndigkeit.<\/p>\n\n\n<div id=\"cve-check\" style=\"scroll-margin-top:100px\"><\/div>\n\n\n\n\t<div class=\"wp-block-lr-cve-quick-check lr-cveqc\">\n\t\t<div class=\"lr-cveqc-inner\">\n\n\t\t\t<div class=\"lr-cveqc-story\">\n\t\t\t\t<h2 class=\"lr-cveqc-headline\">CVE Quick Check<\/h2>\n\t\t\t\t<p class=\"lr-cveqc-text\">Pr\u00fcfen Sie in wenigen Minuten, ob zu einer aktuellen CVE Hinweise auf Ihrer extern sichtbaren Angriffsfl\u00e4che erkennbar sind.<\/p>\n\n\t\t\t\t<ul class=\"lr-cveqc-bullets\">\n\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Grobe Einsch\u00e4tzung in wenigen Minuten per E-Mail.<\/span><\/li>\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Details im kostenlosen Gespr\u00e4ch mit einem LocateRisk Consultant.<\/span><\/li>\t\t\t\t<\/ul>\n\n\t\t\t\t\t\t\t\t<div class=\"lr-cveqc-teaser\" aria-hidden=\"true\">\n\t\t\t\t\t<h4>Das erhalten Sie per E-Mail<\/h4>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Unternehmen<\/span><span class=\"v\">Ihre Firma GmbH<\/span><\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Gepr\u00fcfte CVE<\/span><span class=\"v\">CVE-2026-93029<\/span><\/div>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Passive Bewertung<\/span><span class=\"lr-cveqc-lamp\"><i class=\"r\"><\/i><i class=\"y\"><\/i><i class=\"g\"><\/i><\/span><\/div>\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Hinweise zur CVE<\/span><span class=\"lr-cveqc-pill\">gefunden oder nicht gefunden<\/span><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t<div class=\"lr-cveqc-form-col\">\n\t\t\t\t<form id=\"lr-cveqc-1\" class=\"lr-cveqc-form\" method=\"post\" novalidate\n\t\t\t\t\tdata-ajax-url=\"https:\/\/locaterisk.com\/wp-admin\/admin-ajax.php\">\n\n\t\t\t\t\t<input type=\"text\" name=\"cveId\" required maxlength=\"40\"\n\t\t\t\t\t\tpattern=\"^[Cc][Vv][Ee]-\\d{4}-\\d{4,7}$\"\n\t\t\t\t\t\tvalue=\"CVE-2026-93029\"\n\t\t\t\t\t\tplaceholder=\"CVE-ID, z. B. CVE-2024-3094\" \/>\n\n\t\t\t\t\t<input type=\"email\" name=\"email\" required maxlength=\"320\"\n\t\t\t\t\t\tplaceholder=\"Gesch\u00e4ftliche E-Mail-Adresse\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Bitte verwenden Sie Ihre gesch\u00e4ftliche E-Mail-Adresse. Die Pr\u00fcfung bezieht sich auf das Unternehmen hinter Ihrer E-Mail-Domain; Free-Mail-Adressen (z. B. Gmail) k\u00f6nnen keinem Unternehmen zugeordnet werden.<\/p>\n\n\t\t\t\t\t<!-- Optionale Telefonnummer: nur wer sie angibt, willigt laut Consent-Text\n\t\t\t\t\t     auch in eine telefonische Rueckmeldung ein. autocomplete=\"tel\" ist\n\t\t\t\t\t     gewollt (echtes Feld, kein Honeypot). -->\n\t\t\t\t\t<input type=\"tel\" name=\"phone\" maxlength=\"64\" autocomplete=\"tel\"\n\t\t\t\t\t\tplaceholder=\"Telefon (optional)\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Nur n\u00f6tig, wenn Sie eine kurze telefonische Einordnung m\u00f6chten.<\/p>\n\n\t\t\t\t\t<!-- Honeypot: f\u00fcr Menschen unsichtbar, Bots f\u00fcllen es aus.\n\t\t\t\t\t     Neutraler Feldname (NICHT \"website\"\/\"url\"\/\"email\"), sonst f\u00fcllen\n\t\t\t\t\t     Passwort-Manager und Browser-Autofill das Feld beim echten Nutzer\n\t\t\t\t\t     und blocken ihn faelschlich. -->\n\t\t\t\t\t<div class=\"lr-cveqc-hp\" aria-hidden=\"true\">\n\t\t\t\t\t\t<label>Dieses Feld bitte leer lassen\n\t\t\t\t\t\t\t<input type=\"text\" name=\"lr_hp_check\" tabindex=\"-1\" autocomplete=\"off\" \/>\n\t\t\t\t\t\t<\/label>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"consentProcessingAccepted\" value=\"1\" required \/>\n\t\t\t\t\t\t<span>Ich stimme zu, dass LocateRisk meine Angaben f\u00fcr den Quick Check verarbeitet, mir das Ergebnis per E-Mail schickt und sich dazu per E-Mail bei mir meldet. Es gelten die <a href=\"\/files\/agb.pdf\" target=\"_blank\" rel=\"noopener\">AGB<\/a> und die <a href=\"\/datenschutz\/\" target=\"_blank\" rel=\"noopener\">Datenschutzerkl\u00e4rung<\/a>.<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"cveNotifyOptIn\" value=\"1\" \/>\n\t\t\t\t\t\t<span>Benachrichtigt mich, wenn f\u00fcr extern erkennbare Software neue kritische Schwachstellen (CVSS ab 9) ver\u00f6ffentlicht werden. Jederzeit abbestellbar. (optional)<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"marketingOptIn\" value=\"1\" \/>\n\t\t\t\t\t\t<span>Infos zu LocateRisk Produkten und Security-Themen per E-Mail. Jederzeit widerrufbar. (optional)<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t\t\t\t\t\t<input type=\"hidden\" name=\"consentTextVerbatim\" value=\"Ich stimme zu, dass LocateRisk meine Angaben f\u00fcr den Quick Check verarbeitet, mir das Ergebnis per E-Mail schickt und sich dazu per E-Mail bei mir meldet. Es gelten die AGB und die Datenschutzerkl\u00e4rung.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"consentTextVersion\" value=\"qc_consent_fd4a0945\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"marketingTextVerbatim\" value=\"Infos zu LocateRisk Produkten und Security-Themen per E-Mail. Jederzeit widerrufbar. (optional)\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"marketingTextVersion\" value=\"qc_marketing_cee62603\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"locale\" value=\"en\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"blogPostUrl\" value=\"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmSource\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmCampaign\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"invalidCveMessage\" value=\"Bitte geben Sie eine g\u00fcltige CVE-ID an (z. B. CVE-2024-3094).\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"consentRequiredMessage\" value=\"Bitte stimmen Sie der Verarbeitung zu, damit wir den Quick Check durchf\u00fchren k\u00f6nnen.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"captchaMessage\" value=\"Bitte best\u00e4tigen Sie das reCAPTCHA und versuchen Sie es erneut.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"successMessage\" value=\"Vielen Dank! Bitte best\u00e4tigen Sie Ihre E-Mail-Adresse \u00fcber den Link, den wir Ihnen soeben geschickt haben. Danach starten wir den Quick Check.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"errorMessage\" value=\"Das hat leider nicht geklappt. Bitte pr\u00fcfen Sie Ihre Angaben und versuchen Sie es erneut.\" \/>\n\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"g-recaptcha\" data-sitekey=\"6LdErNoZAAAAAD1Re2jNxtDFfcDaL9iED5MRBzjR\"\n\t\t\t\t\t\t\tdata-callback=\"verifyRecaptchaCallback\" data-expired-callback=\"expiredRecaptchaCallback\"><\/div>\n\t\t\t\t\t\t<input type=\"hidden\" name=\"g-recaptcha-response\" data-recaptcha \/>\n\t\t\t\t\t\n\t\t\t\t\t<p class=\"lr-cveqc-message\" hidden><\/p>\n\n\t\t\t\t\t<button class=\"lr-button-link\" type=\"submit\">Quick Check starten<\/button>\n\t\t\t\t<\/form>\n\t\t\t<\/div>\n\n\t\t<\/div>\n\t<\/div>\n\n\t\t<style>\n\t\t\/* CVE Quick Check im Stil der bestehenden Anfrage-Formulare:\n\t\t   wei\u00dfer Grund, zweispaltig, graue Felder, t\u00fcrkiser Button. *\/\n\t\t.lr-cveqc {\n\t\t\tbackground: #ffffff; color: #00051d; box-sizing: border-box; padding: 64px 32px;\n\t\t\tfont-family: Roboto, -apple-system, BlinkMacSystemFont, \"Segoe UI\", Helvetica, Arial, sans-serif;\n\t\t}\n\t\t.lr-cveqc * { box-sizing: border-box; }\n\t\t.lr-cveqc-inner {\n\t\t\tmax-width: 1160px; margin: 0 auto;\n\t\t\tdisplay: flex; flex-direction: row; gap: 6%; align-items: flex-start;\n\t\t}\n\t\t.lr-cveqc-story { flex: 1 1 54%; min-width: 0; }\n\t\t.lr-cveqc-form-col { flex: 0 0 38%; max-width: 420px; }\n\n\t\t.lr-cveqc-headline { color: #26d9c3; margin: 0 0 20px; }\n\t\t.lr-cveqc-text { font-size: 16px; line-height: 1.62; color: #00051d; margin: 0 0 28px; max-width: 46ch; }\n\n\t\t.lr-cveqc-bullets { list-style: none; margin: 0 0 30px; padding: 0; display: flex; flex-direction: column; gap: 16px; }\n\t\t.lr-cveqc-bullets li { display: flex; gap: 13px; align-items: flex-start; }\n\t\t.lr-cveqc-bullets svg { flex: none; width: 25px; height: 25px; margin-top: 1px; }\n\t\t.lr-cveqc-bullets span { font-size: 15px; line-height: 1.5; color: #00051d; }\n\n\t\t.lr-cveqc-teaser { border: 1px solid #e2e8e6; border-radius: 12px; padding: 18px 20px; background: linear-gradient(180deg,#fbfdfc,#f2f8f6); max-width: 430px; }\n\t\t.lr-cveqc-teaser h4 { margin: 0 0 6px; font-size: 11px; letter-spacing: .15em; text-transform: uppercase; color: #58616f; font-family: inherit; font-weight: 700; }\n\t\t.lr-cveqc-trow { display: flex; align-items: center; justify-content: space-between; gap: 10px; padding: 7px 0; font-size: 13.5px; }\n\t\t.lr-cveqc-trow + .lr-cveqc-trow { border-top: 1px dashed #dbe4e1; }\n\t\t.lr-cveqc-trow .k { color: #58616f; }\n\t\t.lr-cveqc-trow .v { font-weight: 600; color: #00051d; }\n\t\t.lr-cveqc-lamp { display: inline-flex; gap: 6px; align-items: center; }\n\t\t.lr-cveqc-lamp i { width: 13px; height: 13px; border-radius: 50%; opacity: .28; display: inline-block; }\n\t\t.lr-cveqc-lamp i.r { background: #f6105f; }\n\t\t.lr-cveqc-lamp i.y { background: #f6bf28; }\n\t\t.lr-cveqc-lamp i.g { background: #23c39a; }\n\t\t.lr-cveqc-pill { font-size: 12px; font-weight: 700; padding: 3px 10px; border-radius: 999px; background: #eef0f4; color: #00051d; white-space: nowrap; }\n\n\t\t.lr-cveqc-form input[type=text], .lr-cveqc-form input[type=email], .lr-cveqc-form input[type=tel] {\n\t\t\tdisplay: block; width: 100%; height: 50px; margin: 0 0 10px;\n\t\t\tborder: 0; border-radius: 0; background: #dedede; color: #00051d;\n\t\t\tfont-size: 16px; padding: 0 18px; font-family: inherit;\n\t\t}\n\t\t.lr-cveqc-form input::placeholder { color: #6d7580; }\n\t\t.lr-cveqc-form input.lr-invalid { border-bottom: 2px solid #f6105f; }\n\t\t.lr-cveqc-hint { font-size: 12.5px; line-height: 1.5; color: #58616f; margin: 2px 0 16px; }\n\t\t.lr-cveqc-hp { position: absolute !important; left: -9999px !important; height: 0; overflow: hidden; }\n\t\t.lr-cveqc-check { display: flex; gap: 12px; align-items: flex-start; margin: 0 0 12px; font-size: 12.5px; line-height: 1.5; color: #00051d; }\n\t\t.lr-cveqc-check span { color: #00051d; }\n\t\t.lr-cveqc-check input { margin-top: 2px; flex: none; width: 18px; height: 18px; accent-color: #26d9c3; }\n\t\t.lr-cveqc-check a { color: inherit; text-decoration: underline; }\n\t\t.lr-cveqc .g-recaptcha { margin: 8px 0 16px; }\n\t\t.lr-cveqc-message { font-size: 14px; padding: 12px 14px; border-radius: 6px; margin: 0 0 12px; }\n\t\t.lr-cveqc-message.lr-success { background: #e2f7ef; color: #0c6b4d; }\n\t\t.lr-cveqc-message.lr-error { background: #fdeaee; color: #9b0e3f; }\n\t\t.lr-cveqc .lr-button-link, .lr-cveqc button[type=submit] {\n\t\t\tdisplay: flex; align-items: center; justify-content: center;\n\t\t\twidth: 100%; height: 50px; padding: 0 20px; box-sizing: border-box;\n\t\t\tborder: 0; cursor: pointer;\n\t\t\tbackground: #26d9c3; color: #00051d; font-weight: 700; font-size: 14px;\n\t\t\tfont-family: inherit; text-align: center; line-height: 1.2; text-decoration: none;\n\t\t\ttransition: background .15s ease;\n\t\t}\n\t\t.lr-cveqc button[type=submit]:hover { background: #0fb5a2; }\n\t\t.lr-cveqc button[disabled] { opacity: .6; cursor: default; }\n\n\t\t@media (max-width: 820px) {\n\t\t\t.lr-cveqc { padding: 40px 22px; }\n\t\t\t.lr-cveqc-inner { flex-direction: column; gap: 34px; }\n\t\t\t.lr-cveqc-story, .lr-cveqc-form-col { flex-basis: auto; max-width: 520px; width: 100%; }\n\t\t}\n\t<\/style>\n\t<script>\n\t(function () {\n\t\t\/\/ Token-Callbacks f\u00fcrs globale reCAPTCHA (identisch zum Theme, defensiv)\n\t\tif (!window.verifyRecaptchaCallback) {\n\t\t\twindow.verifyRecaptchaCallback = function (response) {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = response })\n\t\t\t}\n\t\t}\n\t\tif (!window.expiredRecaptchaCallback) {\n\t\t\twindow.expiredRecaptchaCallback = function () {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = '' })\n\t\t\t}\n\t\t}\n\n\t\tfunction showMessage(form, text, isSuccess) {\n\t\t\tvar box = form.querySelector('.lr-cveqc-message')\n\t\t\tbox.textContent = text\n\t\t\tbox.classList.remove('lr-success', 'lr-error')\n\t\t\tbox.classList.add(isSuccess ? 'lr-success' : 'lr-error')\n\t\t\tbox.hidden = false\n\t\t}\n\n\t\tfunction init() {\n\t\t\tdocument.querySelectorAll('.lr-cveqc-form').forEach(function (form) {\n\t\t\t\tform.addEventListener('submit', function (e) {\n\t\t\t\t\te.preventDefault()\n\n\t\t\t\t\tvar cve = form.querySelector('input[name=cveId]')\n\t\t\t\t\tvar email = form.querySelector('input[name=email]')\n\t\t\t\t\tvar consent = form.querySelector('input[name=consentProcessingAccepted]')\n\t\t\t\t\tvar cvePattern = \/^CVE-\\d{4}-\\d{4,7}$\/i\n\n\t\t\t\t\tcve.classList.toggle('lr-invalid', !cvePattern.test(cve.value.trim()))\n\t\t\t\t\temail.classList.toggle('lr-invalid', !email.checkValidity())\n\n\t\t\t\t\tif (!cvePattern.test(cve.value.trim())) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=invalidCveMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!email.checkValidity()) {\n\t\t\t\t\t\temail.reportValidity()\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!consent.checked) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=consentRequiredMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\n\t\t\t\t\tvar button = form.querySelector('button[type=submit]')\n\t\t\t\t\tbutton.disabled = true\n\n\t\t\t\t\tvar data = new FormData(form)\n\t\t\t\t\tdata.append('action', 'lr_cve_quick_check')\n\n\t\t\t\t\tfetch(form.getAttribute('data-ajax-url'), { method: 'POST', body: data })\n\t\t\t\t\t\t.then(function (res) { return res.json() })\n\t\t\t\t\t\t.then(function (json) {\n\t\t\t\t\t\t\tif (json && json.success) {\n\t\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=successMessage]').value, true)\n\t\t\t\t\t\t\t\tform.querySelectorAll('input, button').forEach(function (el) { el.disabled = true })\n\t\t\t\t\t\t\t} else {\n\t\t\t\t\t\t\t\t\/\/ Interne Codes nie roh anzeigen, nur bekannte Codes auf\n\t\t\t\t\t\t\t\t\/\/ konfigurierte Texte mappen, sonst generische Fehlermeldung\n\t\t\t\t\t\t\t\tvar code = json && json.data && (json.data.code || json.data.message)\n\t\t\t\t\t\t\t\tvar msg = form.querySelector('input[name=errorMessage]').value\n\t\t\t\t\t\t\t\tif (code === 'invalid_cve' || code === 'invalid') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=invalidCveMessage]').value\n\t\t\t\t\t\t\t\t} else if (code === 'captcha') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=captchaMessage]').value\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t\tshowMessage(form, msg, false)\n\t\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t\t\tif (window.grecaptcha && form.querySelector('.g-recaptcha')) {\n\t\t\t\t\t\t\t\t\ttry { window.grecaptcha.reset() } catch (err) { \/* noop *\/ }\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t}\n\t\t\t\t\t\t})\n\t\t\t\t\t\t.catch(function () {\n\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=errorMessage]').value, false)\n\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t})\n\t\t\t\t})\n\t\t\t})\n\t\t}\n\n\t\tif (document.readyState === 'loading') {\n\t\t\tdocument.addEventListener('DOMContentLoaded', init)\n\t\t} else {\n\t\t\tinit()\n\t\t}\n\t})()\n\t<\/script>\n\t\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<div class=\"wp-block-lr-contact-module\"><div class=\"content\"><h2>Mehr erfahren, Demo buchen oder einfach mal kurz austauschen? Wir freuen uns!<\/h2><div class=\"contact-info-row\"><div class=\"contact-person-info\"><div class=\"avatar\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2025\/06\/Lukas_Baumann_LocateRisk-300.png\"><\/div><p><span class=\"text before\">Ihr Ansprechpartner<\/span><span class=\"bold name\"><strong>Lukas<\/strong><\/span> <span class=\"lastname\"><strong>Baumann<strong><\/strong><\/strong><\/span><strong><strong><span class=\"separator\"><\/span><span class=\"role\">CEO<\/span><\/strong><\/strong><\/p><\/div><p class=\"bold phone\"><strong><strong>+49 6151 6290246<\/strong><\/strong><\/p><strong><strong><a class=\"pr-1\" href=\"mailto:%20sales@locaterisk.com\">Jetzt Kontakt aufnehmen<\/a><\/strong><\/strong><\/div><\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div class=\"wp-block-lr-footer-module lr-footer-block\"><div class=\"content\"><div class=\"column0\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/assets\/img\/lr-logo.svg\"\/><\/div><div class=\"categories\"><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/\">Home<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">Blog<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/know\/\">Wissen<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/about\/\">\u00dcber uns<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/contact\/\">Kontakt<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/legal-notice\/\">Impressum<\/a><\/div><div class=\"categories-break\"><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/privacy-policy\/\">Datenschutz<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/files\/agb.pdf\">AGB<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/jobs\/\">Jobs<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/app.secfix.com\/trust\/locaterisk\/d1e7d433b33643aea1880bfbfeab9f60\">Trust Center<\/a><\/div><\/div><div class=\"social\"><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/10\/gruppe-230@3x.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.instagram.com\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Instagram.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/locaterisk\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/twitter.png\"\/><\/a><\/div><\/div><div class=\"description\"><h6>\u00a9 LocateRisk 2026<\/h6><\/div><\/div><\/div>\n\n\n\n<style id=\"lr-ol-fix\">body>div>ol,.entry-content>div>ol{max-width:843px;margin:0 auto;padding:20px 0;font-family:Roboto;font-size:1.25rem;line-height:1.67;color:#ffffff}.blog-post ol.wp-block-list{padding-left:3rem}<\/style>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2026-93029 affects a stored XSS vulnerability in the WHM interface Manage SSL Hosts with a CVSS score of 9.0.<\/p>","protected":false},"author":13,"featured_media":9138,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[632],"tags":[942],"lr_blog_topic":[837],"class_list":["post-99173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news","tag-cpanel-whm-stored-xss-cve-2026-93029","lr_blog_topic-schwachstellen-advisories"],"yoast_head":"<title>CVE-2026-93029: Stored XSS in cPanel WHM<\/title>\n<meta name=\"description\" content=\"CVE-2026-93029 betrifft eine Stored-XSS-Schwachstelle im WHM-Interface Manage SSL Hosts mit einem CVSS-Score von 9.0.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-93029: Stored XSS in cPanel WHM\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-93029 betrifft eine Stored-XSS-Schwachstelle im WHM-Interface Manage SSL Hosts mit einem CVSS-Score von 9.0.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-02T12:31:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kristina Hoinkis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristina Hoinkis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/\"},\"author\":{\"name\":\"Kristina Hoinkis\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\"},\"headline\":\"CVE-2026-93029: Stored XSS im cPanel-WHM-Interface\",\"datePublished\":\"2026-10-02T12:31:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/\"},\"wordCount\":776,\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"keywords\":[\"cpanel-whm-stored-xss-cve-2026-93029\"],\"articleSection\":[\"Cybersecurity News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/\",\"name\":\"CVE-2026-93029: Stored XSS in cPanel WHM\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"datePublished\":\"2026-10-02T12:31:42+00:00\",\"description\":\"CVE-2026-93029 betrifft eine Stored-XSS-Schwachstelle im WHM-Interface Manage SSL Hosts mit einem CVSS-Score von 9.0.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#primaryimage\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"width\":400,\"height\":400,\"caption\":\"vulnerability-disclosure\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/cpanel-whm-stored-xss-cve-2026-93029\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-93029: Stored XSS im cPanel-WHM-Interface\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\",\"name\":\"Kristina Hoinkis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"caption\":\"Kristina Hoinkis\"}}]}<\/script>","yoast_head_json":{"title":"CVE-2026-93029: Stored XSS in cPanel WHM","description":"CVE-2026-93029 affects a stored XSS vulnerability in the WHM interface Manage SSL Hosts with a CVSS score of 9.0.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-93029: Stored XSS in cPanel WHM","og_description":"CVE-2026-93029 betrifft eine Stored-XSS-Schwachstelle im WHM-Interface Manage SSL Hosts mit einem CVSS-Score von 9.0.","og_url":"https:\/\/locaterisk.com\/en\/cpanel-whm-stored-xss-cve-2026-93029\/","og_site_name":"LocateRisk","article_published_time":"2026-10-02T12:31:42+00:00","og_image":[{"width":400,"height":400,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","type":"image\/png"}],"author":"Kristina Hoinkis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kristina Hoinkis","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#article","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/"},"author":{"name":"Kristina Hoinkis","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32"},"headline":"CVE-2026-93029: Stored XSS im cPanel-WHM-Interface","datePublished":"2026-10-02T12:31:42+00:00","mainEntityOfPage":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/"},"wordCount":776,"publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"image":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","keywords":["cpanel-whm-stored-xss-cve-2026-93029"],"articleSection":["Cybersecurity News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/","url":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/","name":"CVE-2026-93029: Stored XSS in cPanel WHM","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#primaryimage"},"image":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","datePublished":"2026-10-02T12:31:42+00:00","description":"CVE-2026-93029 affects a stored XSS vulnerability in the WHM interface Manage SSL Hosts with a CVSS score of 9.0.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#primaryimage","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","width":400,"height":400,"caption":"vulnerability-disclosure"},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/de\/cpanel-whm-stored-xss-cve-2026-93029\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-93029: Stored XSS im cPanel-WHM-Interface"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]},{"@type":"Person","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32","name":"Kristina Hoinkis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","caption":"Kristina Hoinkis"}}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/comments?post=99173"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99173\/revisions"}],"predecessor-version":[{"id":99174,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99173\/revisions\/99174"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media\/9138"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/categories?post=99173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/tags?post=99173"},{"taxonomy":"lr_blog_topic","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/lr_blog_topic?post=99173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}