PatchSiren

ispconfig CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ispconfig CVE published 2026-08-19

CVE-2026-61518

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. A remote API user holding any single low-privilege function permission can inject arbitrary SQL to delete or modify records across all tenants in the contro [truncated]

MEDIUM ISPConfig CVE published 2026-05-05

CVE-2025-52206

CVE-2025-52206 is a Cross Site Scripting (XSS) vulnerability in ISPConfig 3.3.0 via the system status webpage. The vulnerability has a CVSS score of 4.7 and a severity of MEDIUM. This vulnerability allows an attacker to inject malicious JavaScript code, potentially leading to unauthorized actions or data exposure. Users of ISPConfig 3.3.0 should be aware of this vulnerability and take steps to mitigate it [truncated]