VYPR

Hestiacp

by Hestiacp

Source repositories

CVEs (22)

  • CVE-2026-43633CriMay 19, 2026
    risk 0.58cvss 10.0epss 0.01

    HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution. Attackers can inject crafted…

  • CVE-2021-47871HigJan 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific…

  • CVE-2025-30007HigJul 10, 2026
    risk 0.50cvss 8.8epss 0.02

    HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient…

  • CVE-2026-43634HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.00

    HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated…

  • CVE-2021-27231MedFeb 16, 2021
    risk 0.35cvss 5.4epss 0.01

    Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

  • CVE-2025-30008MedJul 10, 2026
    risk 0.23cvss 4.6epss 0.00

    HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply…

  • CVE-2022-2550HigJul 27, 2022
    risk 0.04cvss 8.8epss 0.48

    OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

  • CVE-2026-12196HigJul 4, 2026
    risk 0.00cvss epss 0.00

    HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the…

  • CVE-2023-5839HigOct 29, 2023
    risk 0.00cvss 7.8epss 0.00

    Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.

  • CVE-2023-4517MedOct 13, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.

  • CVE-2023-5084LowSep 20, 2023
    risk 0.00cvss 3.9epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.

  • CVE-2023-3479MedJun 30, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

  • CVE-2021-30071MedAug 18, 2022
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2021-30070HigAug 18, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.

  • CVE-2022-2636HigAug 5, 2022
    risk 0.00cvss 8.5epss 0.01

    Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-2626HigAug 5, 2022
    risk 0.00cvss 7.2epss 0.01

    Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-1509CriApr 28, 2022
    risk 0.00cvss 9.9epss 0.05

    Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

  • CVE-2022-0986MedMar 16, 2022
    risk 0.00cvss 6.1epss 0.01

    Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

  • CVE-2022-0752MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.

  • CVE-2022-0838MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

Page 1 of 2