Vestacp
Products
3- 18 CVEs
- 10 CVEs
- 10 CVEs
Recent CVEs
26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10808 | Hig | 0.66 | 8.8 | 0.78 | Mar 22, 2020 | Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring… | ||
| CVE-2020-36948 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2026 | VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper… | ||
| CVE-2021-43693 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2021 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. | ||
| CVE-2018-1000884 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2018 | Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vulnerability in Password reset code -- web/reset/index.php, line 51 that can result in Possible to… | ||
| CVE-2021-28379 | Hig | 0.61 | 8.8 | 0.06 | Mar 15, 2021 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. | ||
| CVE-2015-4117 | Hig | 0.61 | 8.8 | 0.11 | Feb 28, 2018 | Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php. | ||
| CVE-2020-10786 | Hig | 0.58 | 8.8 | 0.05 | Apr 21, 2020 | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs. | ||
| CVE-2019-12792 | Hig | 0.58 | 8.8 | 0.05 | Aug 15, 2019 | A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. | ||
| CVE-2019-12791 | Hig | 0.58 | 8.8 | 0.07 | Aug 15, 2019 | A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form. | ||
| CVE-2020-10787 | Hig | 0.57 | 8.8 | 0.03 | Apr 21, 2020 | An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script). | ||
| CVE-2019-9859 | Hig | 0.57 | 8.8 | 0.03 | Mar 10, 2020 | Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the server. The platform works with PHP as the frontend language and uses shell scripts to execute system actions. PHP executes shell… | ||
| CVE-2018-25117 | Cri | 0.53 | — | 0.00 | Oct 15, 2025 | VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a… | ||
| CVE-2021-30463 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2021 | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a… | ||
| CVE-2021-47873 | Hig | 0.47 | 7.2 | 0.00 | Jan 21, 2026 | VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a… | ||
| CVE-2021-30462 | Hig | 0.47 | 7.2 | 0.02 | Apr 8, 2021 | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. | ||
| CVE-2020-10966 | Med | 0.42 | 6.5 | 0.02 | Mar 25, 2020 | In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name. | ||
| CVE-2022-36305 | Med | 0.40 | 6.1 | 0.01 | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php. | ||
| CVE-2022-36304 | Med | 0.40 | 6.1 | 0.01 | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php. | ||
| CVE-2022-36303 | Med | 0.40 | 6.1 | 0.01 | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php. | ||
| CVE-2022-34025 | Med | 0.40 | 6.1 | 0.01 | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php. |
- risk 0.66cvss 8.8epss 0.78
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring…
- risk 0.64cvss 9.8epss 0.01
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper…
- risk 0.64cvss 9.8epss 0.01
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
- risk 0.64cvss 9.8epss 0.01
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vulnerability in Password reset code -- web/reset/index.php, line 51 that can result in Possible to…
- risk 0.61cvss 8.8epss 0.06
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
- risk 0.61cvss 8.8epss 0.11
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
- risk 0.58cvss 8.8epss 0.05
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
- risk 0.58cvss 8.8epss 0.05
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
- risk 0.58cvss 8.8epss 0.07
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
- risk 0.57cvss 8.8epss 0.03
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).
- risk 0.57cvss 8.8epss 0.03
Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the server. The platform works with PHP as the frontend language and uses shell scripts to execute system actions. PHP executes shell…
- risk 0.53cvss —epss 0.00
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a…
- risk 0.51cvss 7.8epss 0.01
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a…
- risk 0.47cvss 7.2epss 0.00
VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a…
- risk 0.47cvss 7.2epss 0.02
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
- risk 0.42cvss 6.5epss 0.02
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
- risk 0.40cvss 6.1epss 0.01
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
- risk 0.40cvss 6.1epss 0.01
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
- risk 0.40cvss 6.1epss 0.01
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
- risk 0.40cvss 6.1epss 0.01
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.