ispconfig 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk cross-site scripting and vendor risk csrf などに関し、一部は vendor impact session compromise を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-52206 | ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage. | [email protected] | 4.7 | 0.03% | 2026-05-05 | 2026-05-12 |
| CVE-2023-46818 | An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. | [email protected] | 7.2 | 90.53% | 2023-10-27 | 2024-11-21 |
| CVE-2021-3021 | ISPConfig before 3.2.2 allows SQL injection. | [email protected] | 9.8 | 0.44% | 2021-01-05 | 2024-11-21 |
| CVE-2020-9398 | ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection. | [email protected] | 9.8 | 0.51% | 2020-02-25 | 2024-11-21 |
| CVE-2013-3629 | ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution | [email protected] | 8.8 | 76.43% | 2020-02-07 | 2024-11-21 |
| CVE-2012-2087 | ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface. | [email protected] | 9.8 | 3.27% | 2020-01-23 | 2024-11-21 |
| CVE-2018-17984 | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access. | [email protected] | 7.8 | 0.44% | 2018-10-04 | 2024-11-21 |
| CVE-2017-17384 | ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. | [email protected] | 8.8 | 0.51% | 2017-12-07 | 2026-05-13 |
| CVE-2015-4119 | Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php. | [email protected] | 6.8 | 4.61% | 2015-06-15 | 2026-05-06 |
| CVE-2015-4118 | SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2. | [email protected] | 6.5 | 1.91% | 2015-06-15 | 2026-05-06 |
| CVE-2006-3042 | Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after install | [email protected] | 7.5 | 7.20% | 2006-06-15 | 2026-04-16 |
| CVE-2006-2315 | PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled | [email protected] | 7.5 | 12.99% | 2006-05-12 | 2026-04-16 |