Search
Search Results (17 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-30007 | 1 Hestiacp | 2 Control Panel, Hestiacp | 2026-07-13 | 8.8 High |
| HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in is_dns_record_format_valid() combined with unsafe eval-based parsing in update_domain_zone() to prematurely close a variable assignment string and achieve full root code execution on the underlying host in a single DNS record creation step. | ||||
| CVE-2025-30008 | 1 Hestiacp | 2 Control Panel, Hestiacp | 2026-07-10 | 4.6 Medium |
| HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record value field rendered into the data-sort-value HTML attribute in list_dns_rec.php, allowing the payload to execute in the browser of any user who views the DNS record list, including administrators. | ||||
| CVE-2021-47871 | 1 Hestiacp | 1 Control Panel | 2026-04-15 | 8.8 High |
| Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server. | ||||
| CVE-2022-2636 | 1 Hestiacp | 1 Control Panel | 2026-02-25 | 8.5 High |
| Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||||
| CVE-2023-5839 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 7.8 High |
| Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. | ||||
| CVE-2023-3479 | 1 Hestiacp | 2 Control Panel, Hestiacp | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. | ||||
| CVE-2022-2626 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 7.2 High |
| Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||||
| CVE-2022-2550 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 8.8 High |
| OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. | ||||
| CVE-2022-1509 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 9.9 Critical |
| Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. | ||||
| CVE-2022-0986 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 6.1 Medium |
| Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. | ||||
| CVE-2022-0838 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. | ||||
| CVE-2022-0753 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. | ||||
| CVE-2022-0752 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. | ||||
| CVE-2021-3797 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 9.8 Critical |
| hestiacp is vulnerable to Use of Wrong Operator in String Comparison | ||||
| CVE-2021-30071 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||||
| CVE-2021-27231 | 1 Hestiacp | 1 Control Panel | 2024-11-21 | 5.4 Medium |
| Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages. | ||||
| CVE-2020-10966 | 2 Hestiacp, Vestacp | 2 Control Panel, Control Panel | 2024-11-21 | 6.5 Medium |
| In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name. | ||||
Page 1 of 1.