Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control Panel MEDIUM 5.4
CVE-2025-30008

HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by …

Fix: 1.9.5+
Fix from $1,600 2026-07-10
Control Panel HIGH 8.8
CVE-2025-30007

HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary…

Fix: 1.9.5+
Fix from $1,950 2026-07-10
Control Panel HIGH 7.8
CVE-2023-5839

Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.

Fix: 1.8.9+
Fix from $1,950 2023-10-29
Hestiacp MEDIUM 5.4
CVE-2023-4517

Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.

Fix: 1.8.6+
Fix from $1,600 2023-10-13
Hestiacp MEDIUM 6.1
CVE-2023-5084

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.

Fix: 1.8.8+
Fix from $1,600 2023-09-20
Control Panel MEDIUM 6.1
CVE-2023-3479

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

Fix: 1.7.8+
Fix from $1,600 2023-06-30
Hestiacp HIGH 7.5
CVE-2021-30070

An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter i…

Fix: 1.3.5+
Fix from $1,950 2022-08-18
Control Panel MEDIUM 6.1
CVE-2021-30071

A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTM…

Fix: 1.3.5+
Fix from $1,600 2022-08-18
Control Panel HIGH 8.8
CVE-2022-2636

Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.

Fix: 1.6.6+
Fix from $1,950 2022-08-05
Control Panel HIGH 7.2
CVE-2022-2626

Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

Fix: 1.6.6+
Fix from $1,950 2022-08-05
Control Panel HIGH 8.8
CVE-2022-2550EPSS 48%

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

Fix: 1.6.5+
Fix from $1,950 2022-07-27
Control Panel HIGH 8.8
CVE-2022-1509

Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can exec…

Fix: 1.5.12+
Fix from $1,950 2022-04-28
Control Panel MEDIUM 6.1
CVE-2022-0986

Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

Fix: 1.5.11+
Fix from $1,600 2022-03-16
Control Panel MEDIUM 6.1
CVE-2022-0752

Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.

Fix: 1.5.9+
Fix from $1,600 2022-03-04
Control Panel MEDIUM 6.1
CVE-2022-0838

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

Fix: 1.5.10+
Fix from $1,600 2022-03-04
Control Panel MEDIUM 6.1
CVE-2022-0753

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.

Fix: 1.5.9+
Fix from $1,600 2022-03-03
Control Panel CRITICAL 9.8
CVE-2021-3797

hestiacp is vulnerable to Use of Wrong Operator in String Comparison

Fix: after 1.4.12
Fix from $2,300 2021-09-15
Control Panel MEDIUM 5.4
CVE-2021-27231

Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a differ…

Fix: after 1.3.5
Fix from $1,600 2021-02-16
Control Panel MEDIUM 6.5
CVE-2020-10966

In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account…

Fix: 1.1.1+
Fix from $1,600 2020-03-25