VYPR

VestaCP

by Vestacp

Source repositories

CVEs (10)

  • CVE-2020-36948CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper…

  • CVE-2021-43693CriNov 29, 2021
    risk 0.64cvss 9.8epss 0.01

    vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

  • CVE-2019-12792HigAug 15, 2019
    risk 0.58cvss 8.8epss 0.05

    A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.

  • CVE-2018-25117CriOct 15, 2025
    risk 0.53cvss epss 0.00

    VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a…

  • CVE-2021-30463HigApr 8, 2021
    risk 0.51cvss 7.8epss 0.01

    VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a…

  • CVE-2021-47873HigJan 21, 2026
    risk 0.47cvss 7.2epss 0.00

    VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a…

  • CVE-2021-30462HigApr 8, 2021
    risk 0.47cvss 7.2epss 0.02

    VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.

  • CVE-2018-18547MedOct 24, 2018
    risk 0.40cvss 6.1epss 0.01

    Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.

  • CVE-2021-28379HigMar 15, 2021
    risk 0.03cvss 8.8epss 0.06

    web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.

  • CVE-2019-9841MedApr 19, 2019
    risk 0.00cvss 6.1epss 0.01

    Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.