cbcvebase.

Softaculous Virtualizor vulnerabilities

3 known vulnerabilities affecting softaculous/virtualizor.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-43641P1CRITICALCVSS 9.8fixed in 3.2.9 (Patch 9)2026-09-22
CVE-2026-43641 [CRITICAL] CWE-78 CVE-2026-43641: Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerabil Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and
nvd
CVE-2026-43642P2HIGHCVSS 8.1fixed in 3.2.9 (Patch 9)2026-09-22
CVE-2026-43642 [HIGH] CWE-502 CVE-2026-43642: Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerabili Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login with the from_billing_module parameter present. Attackers can pass malicio
nvd
CVE-2026-43643P3HIGHCVSS 7.5fixed in 3.2.9 (Patch 9)2026-09-22
CVE-2026-43643 [HIGH] CWE-862 CVE-2026-43643: Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerabil Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters to the admin panel dispatcher. Attackers can send a POST request with arbit
nvd
Softaculous Virtualizor vulnerabilities | cvebase