Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2025-30008
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by …
Control Panel
1.9.5+
HIGH 8.8
CVE-2025-30007
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary…
Control Panel
1.9.5+
HIGH 7.8
CVE-2023-5839
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
Control Panel
1.8.9+
MEDIUM 5.4
CVE-2023-4517
Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.
Hestiacp
1.8.6+
MEDIUM 6.1
CVE-2023-5084
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
Hestiacp
1.8.8+
MEDIUM 6.1
CVE-2023-3479
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
Control Panel
1.7.8+
HIGH 7.5
CVE-2021-30070
An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter i…
Hestiacp
1.3.5+
MEDIUM 6.1
CVE-2021-30071
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTM…
Control Panel
1.3.5+
HIGH 8.8
CVE-2022-2636
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Control Panel
1.6.6+
HIGH 7.2
CVE-2022-2626
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Control Panel
1.6.6+
HIGH 8.8
CVE-2022-2550EPSS 48%
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
Control Panel
1.6.5+
HIGH 8.8
CVE-2022-1509
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can exec…
Control Panel
1.5.12+
MEDIUM 6.1
CVE-2022-0986
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
Control Panel
1.5.11+
MEDIUM 6.1
CVE-2022-0752
Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
Control Panel
1.5.9+
MEDIUM 6.1
CVE-2022-0838
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
Control Panel
1.5.10+
MEDIUM 6.1
CVE-2022-0753
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
Control Panel
1.5.9+
CRITICAL 9.8
CVE-2021-3797
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
Control Panel
after 1.4.12
MEDIUM 5.4
CVE-2021-27231
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a differ…
Control Panel
after 1.3.5
MEDIUM 6.5
CVE-2020-10966
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account…
Control Panel
1.1.1+