ehcp CVE Vulnerabilities & CVE List (12)

Products (CPE): — CVEs: 12

ehcp vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ehcp-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk sql injection, and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 112 of 12 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-50859 Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. [email protected] 6.1 0.27% 2025-08-22 2026-06-17
CVE-2025-50858 Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. [email protected] 6.1 0.22% 2025-08-22 2026-06-17
CVE-2025-50860 SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. [email protected] 5.4 0.21% 2025-08-21 2026-06-17
CVE-2025-50926 Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. [email protected] 6.5 0.24% 2025-08-19 2026-06-17
CVE-2025-50928 Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. [email protected] 4.8 0.15% 2025-08-08 2026-06-17
CVE-2025-50927 A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. [email protected] 6.3 0.21% 2025-08-08 2026-06-17
CVE-2018-6619 Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt. [email protected] 7.8 0.36% 2018-05-11 2026-06-16
CVE-2018-6618 Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. [email protected] 7.8 0.47% 2018-05-11 2026-06-16
CVE-2018-6617 Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password. [email protected] 7.8 0.43% 2018-05-11 2026-06-16
CVE-2018-6458 Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. [email protected] 8.8 10.46% 2018-05-11 2026-06-16
CVE-2018-6362 Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie. [email protected] 6.1 1.06% 2018-05-11 2026-06-16
CVE-2018-6361 Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. [email protected] 6.1 39.56% 2018-05-11 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence