VestaCP
by Vestacp
Source repositories
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36948 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2026 | VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper… | ||
| CVE-2021-43693 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2021 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. | ||
| CVE-2019-12792 | Hig | 0.58 | 8.8 | 0.05 | Aug 15, 2019 | A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. | ||
| CVE-2018-25117 | Cri | 0.53 | — | 0.00 | Oct 15, 2025 | VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a… | ||
| CVE-2021-30463 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2021 | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a… | ||
| CVE-2021-47873 | Hig | 0.47 | 7.2 | 0.00 | Jan 21, 2026 | VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a… | ||
| CVE-2021-30462 | Hig | 0.47 | 7.2 | 0.02 | Apr 8, 2021 | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. | ||
| CVE-2018-18547 | Med | 0.40 | 6.1 | 0.01 | Oct 24, 2018 | Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI. | ||
| CVE-2021-28379 | Hig | 0.03 | 8.8 | 0.06 | Mar 15, 2021 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. | ||
| CVE-2019-9841 | Med | 0.00 | 6.1 | 0.01 | Apr 19, 2019 | Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. |
- risk 0.64cvss 9.8epss 0.01
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper…
- risk 0.64cvss 9.8epss 0.01
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
- risk 0.58cvss 8.8epss 0.05
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
- risk 0.53cvss —epss 0.00
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a…
- risk 0.51cvss 7.8epss 0.01
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a…
- risk 0.47cvss 7.2epss 0.00
VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a…
- risk 0.47cvss 7.2epss 0.02
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
- risk 0.40cvss 6.1epss 0.01
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.
- risk 0.03cvss 8.8epss 0.06
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
- risk 0.00cvss 6.1epss 0.01
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.