cPanel prior to 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
cpanel cpanel