cbcvebase.
CVE-2026-93697
published 2026-10-02

CVE-2026-93697: There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

PriorityP346critical9CVSS 3.0
AVNACLPRLUIRSCCHIHAH
EPSS
0.40%
32.1th percentile
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

Affected

5 ranges
VendorProductVersion rangeFixed in
webproscpanel< 11.138.0.1111.138.0.11
webproscpanel< 11.136.0.4511.136.0.45
webproscpanel< 11.134.0.6111.134.0.61
webproscpanel< 11.110.0.14811.110.0.148
webproswp_squared< 11.138.1.1311.138.1.13
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.