Filtered by vendor Parallels Subscriptions
Filtered by product Parallels Plesk Panel Subscriptions
Total 42 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2011-4850 2 Microsoft, Parallels 3 Windows 2003 Server, Windows Server 2008, Parallels Plesk Panel 2025-04-11 N/A
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by help.php and certain other files.
CVE-2019-18793 1 Parallels 1 Parallels Plesk Panel 2024-11-21 6.1 Medium
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.