VYPR

Control Panel

by Hestiacp

Source repositories

CVEs (16)

  • CVE-2025-30007HigJul 10, 2026
    risk 0.50cvss 8.8epss 0.02

    HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient…

  • CVE-2021-27231MedFeb 16, 2021
    risk 0.35cvss 5.4epss 0.01

    Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

  • CVE-2025-30008MedJul 10, 2026
    risk 0.23cvss 4.6epss 0.00

    HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply…

  • CVE-2022-2550HigJul 27, 2022
    risk 0.04cvss 8.8epss 0.48

    OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

  • CVE-2023-5839HigOct 29, 2023
    risk 0.00cvss 7.8epss 0.00

    Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.

  • CVE-2023-3479MedJun 30, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

  • CVE-2021-30071MedAug 18, 2022
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-2636HigAug 5, 2022
    risk 0.00cvss 8.5epss 0.01

    Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-2626HigAug 5, 2022
    risk 0.00cvss 7.2epss 0.01

    Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-1509CriApr 28, 2022
    risk 0.00cvss 9.9epss 0.05

    Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

  • CVE-2022-0986MedMar 16, 2022
    risk 0.00cvss 6.1epss 0.01

    Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

  • CVE-2022-0752MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.

  • CVE-2022-0838MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

  • CVE-2022-0753MedMar 3, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.

  • CVE-2021-3797CriSep 15, 2021
    risk 0.00cvss 9.8epss 0.01

    hestiacp is vulnerable to Use of Wrong Operator in String Comparison

  • CVE-2020-10966MedMar 25, 2020
    risk 0.00cvss 6.5epss 0.02

    In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.