hestiacp CVE Vulnerabilities & CVE List (17)

Products (CPE): — CVEs: 17

hestiacp vulnerability overview

Aggregates CVE and security vulnerability intelligence across all hestiacp-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk command injection, with potential vendor impact session compromise across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 117 of 17 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-5839 Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. [email protected] 7.8 0.05% 2023-10-29 2024-11-21
CVE-2023-4517 Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6. [email protected] 5.4 0.07% 2023-10-13 2024-11-21
CVE-2023-5084 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. [email protected] 3.9 0.08% 2023-09-20 2024-11-21
CVE-2023-3479 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. [email protected] 6.1 23.52% 2023-06-30 2024-11-21
CVE-2021-30071 A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. [email protected] 6.1 0.23% 2022-08-18 2024-11-21
CVE-2021-30070 An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager. [email protected] 7.5 0.23% 2022-08-18 2024-11-21
CVE-2022-2636 Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. [email protected] 8.5 0.42% 2022-08-05 2026-02-25
CVE-2022-2626 Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. [email protected] 7.2 0.35% 2022-08-05 2024-11-21
CVE-2022-2550 OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. [email protected] 8.8 8.79% 2022-07-27 2024-11-21
CVE-2022-1509 Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. [email protected] 9.9 1.68% 2022-04-28 2024-11-21
CVE-2022-0986 Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. [email protected] 6.1 0.32% 2022-03-16 2024-11-21
CVE-2022-0752 Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. [email protected] 6.1 0.30% 2022-03-04 2024-11-21
CVE-2022-0838 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. [email protected] 6.1 0.87% 2022-03-04 2024-11-21
CVE-2022-0753 Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. [email protected] 6.1 0.28% 2022-03-03 2024-11-21
CVE-2021-3797 hestiacp is vulnerable to Use of Wrong Operator in String Comparison [email protected] 9.8 0.44% 2021-09-15 2024-11-21
CVE-2021-27231 Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages. [email protected] 5.4 0.32% 2021-02-16 2024-11-21
CVE-2020-10966 In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name. [email protected] 6.5 0.51% 2020-03-25 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence