• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Please beaware of a breaking change in the REST API on the current Plesk release (18.0.62).
    Starting from Plesk Obsidian 18.0.62, requests to REST API containing the Content-Type header with a media-type directive other than “application/json” will result in the HTTP “415 Unsupported Media Type” client error response code. Read more here

Issue unconfigured CSP blocking iframe


New Pleskian
we have moved from a i-mscp vserver to a plesk 18.0.24 administered vserver. We did not configure CSP (contect security policy) yet. However when we want to show an embedded iframe the users get an CSP error (here: Firefox) that this insert was blocked.

So far the provider could not tell us where to look for settings to deactivate any (default?) CSP settings. When I have our domain checked with the Mozilla site checker:
I get the message that there is no CSP implemented and get a -25 score.

Web Application Firefall Mode = OFF

But why do we get an CSP error in the first place when loading a page with an iframe? With i-mscp all worked fine. Is this a plesk issue? Where to look?

thx for some thoughts,
Last edited:
would help if you let us know your OS and how your plesk is configured: only apache, apache/nginx, only nginx, something less common...