Known vulnerabilities in EasyApache 4

Software: EasyApache
Version: 4
Software CPE: cpe:2.3:a:cpanel:easyapache:*:*:*:*:*:*:*:*
Total vulnerabilities: 118
Public exploits: 17
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting EasyApache version 4 EasyApache 4 is affected by 118 vulnerabilities: 3 critical, 14 high, 80 medium, 21 low Critical High Medium Low

Vulnerabilities (118)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130909 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-6735
CWE-79 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130910 - NULL Pointer Dereference
CVE-2026-7259
CWE-476 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 14 more
#VU130912 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-14179
CWE-89 High
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130913 - Use After Free
CVE-2026-6722
CWE-416 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU130914 - Use After Free
CVE-2026-7261
CWE-416 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU130915 - NULL Pointer Dereference
CVE-2026-7262
CWE-476 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130916 - Integer overflow
CVE-2026-7568
CWE-190 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130917 - Type conversion
CVE-2026-7258
CWE-704 Medium
No
No
4 25-58 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
4 25-6 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
4 25-6 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU103686 - Improper Authentication
CVE-2025-23419
CWE-287 Low
No
No
4 25-5 06.02.2025 SB2025020653
SB2025020670
SB2025020671
and 17 more
#VU103648 - Exposure of sensitive information to an unauthorized actor
CVE-2025-0167
CWE-200 Low
No
No
4 25-5 05.02.2025 SB2025020531
SB2025020601
SB2025020658
and 20 more
#VU103647 - Resource Management Errors
CVE-2025-0665
CWE-399 Low
No
No
4 25-5 05.02.2025 SB2025020531
SB2025020601
SB2025022022
and 5 more
#VU103646 - Integer overflow
CVE-2025-0725
CWE-190 High
No
No
4 25-5 05.02.2025 SB2025020531
SB2025020601
SB2025020658
and 25 more
#VU103225 - Missing release of memory after effective lifetime
CVE-2025-23085
CWE-401 Medium
No
No
4 25-4 22.01.2025 SB2025012252
SB2025012439
SB2025012440
and 29 more
#VU103223 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-23084
CWE-22 Low
No
No
4 25-4 22.01.2025 SB2025012252
SB2025012422
SB2025012423
and 11 more
#VU103222 - Permissions, Privileges, and Access Controls
CVE-2025-23083
CWE-264 Low
No
No
4 25-4 22.01.2025 SB2025012252
SB2025012346
SB2025012402
and 21 more
#VU102383 - Use After Free
CVE-2024-46981
CWE-416 Medium
Public exploit available
No
4 25-1, 4 25-2 06.01.2025 SB2025010646
SB2025010647
SB2025010901
and 39 more
#VU101893 - Permissions, Privileges, and Access Controls
CVE-2024-56337
CWE-264 High
No
No
4 25-5 20.12.2024 SB2024122063
SB2025011311
SB2025011801
and 45 more
#VU101813 - Resource exhaustion
CVE-2024-54677
CWE-400 Medium
No
No
4 2024-12-18 17.12.2024 SB2024121745
SB2024121905
SB2024122055
and 13 more


Showing elements 1 - 20 out of 118