VendorsHestiacpcontrol_panelall versions
Vulnerabilities

Hestiacp Hestia Control Panel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-2550
OS Command Injection in hestiacp/hestiacp
Published 2022-07-27 · Modified
9.9EPSS 0.483
CVE-2022-1509
Command Injection Vulnerability in hestiacp/hestiacp
Published 2022-04-28 · Modified
9.9EPSS 0.045
CVE-2021-3797
Use of Wrong Operator in String Comparison in hestiacp/hestiacp
Published 2021-09-15 · Modified
9.8EPSS 0.011
CVE-2022-2626
Incorrect Privilege Assignment in hestiacp/hestiacp
Published 2022-08-05 · Modified
9.1EPSS 0.012
CVE-2025-30007
HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management
Published 2026-07-10 · Analyzed
8.8EPSS 0.032
CVE-2022-2636
Code Injection in hestiacp/hestiacp
Published 2022-08-05 · Modified
8.8EPSS 0.013
CVE-2023-5839
Privilege Chaining in hestiacp/hestiacp
Published 2023-10-29 · Modified
8.8EPSS 0.003
CVE-2022-0838
Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
Published 2022-03-04 · Modified
6.6EPSS 0.011
CVE-2020-10966
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
Published 2020-03-25 · Modified
6.5EPSS 0.019
CVE-2023-3479
Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
Published 2023-06-30 · Modified
6.1EPSS 0.013
CVE-2022-0752
Cross-site Scripting (XSS) - Generic in hestiacp/hestiacp
Published 2022-03-04 · Modified
6.1EPSS 0.010
CVE-2022-0986
Reflected Cross-site Scripting (XSS) Vulnerability in hestiacp/hestiacp
Published 2022-03-16 · Modified
6.1EPSS 0.009
CVE-2022-0753
Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
Published 2022-03-03 · Modified
6.1EPSS 0.008
CVE-2021-30071
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published 2022-08-18 · Modified
6.1EPSS 0.006
CVE-2021-27231
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.
Published 2021-02-16 · Modified
5.5EPSS 0.014
CVE-2025-30008
HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface
Published 2026-07-10 · Analyzed
5.4EPSS 0.003