CVE-2025-20128 & cPanel 110.0.112
It's come to my attention that CVE-2025-20128 (a vulnerability in ClamAV < v1.08) exists on cPanel 110.0.112. According to the plugin manager, our ClamAV for cPanel is Version: 0.104.4.2-4.cp108~el7. I checked the binary and, sure enough, it's from Feb 2024.
Given that cPanel 110 is still seeing LTS, it seems reasonable to have plugins updated to address such vulnerabilities.
Please sign in to leave a comment.
Comments
0 comments