CVE-2026-58046
WebPros Plesk
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
- CVSS
- 9.9
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.30