CVE-2025-30008
- EPSS 0.18%
- Veröffentlicht 10.07.2026 17:51:07
- Zuletzt bearbeitet 20.07.2026 12:57:39
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The applic...
CVE-2025-30007
- EPSS 1.99%
- Veröffentlicht 10.07.2026 17:50:33
- Zuletzt bearbeitet 20.07.2026 13:04:01
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers ...
CVE-2023-5839
- EPSS 0.29%
- Veröffentlicht 29.10.2023 01:15:41
- Zuletzt bearbeitet 21.11.2024 08:42:36
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
CVE-2023-3479
- EPSS 1.29%
- Veröffentlicht 30.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:17:21
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
CVE-2021-30071
- EPSS 0.56%
- Veröffentlicht 18.08.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:03:17
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-2636
- EPSS 1.27%
- Veröffentlicht 05.08.2022 10:15:08
- Zuletzt bearbeitet 25.02.2026 15:19:00
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
CVE-2022-2626
- EPSS 1.22%
- Veröffentlicht 05.08.2022 09:15:07
- Zuletzt bearbeitet 21.11.2024 07:01:23
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
CVE-2022-2550
- EPSS 48.29%
- Veröffentlicht 27.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:13
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
- EPSS 4.59%
- Veröffentlicht 28.04.2022 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:52
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
CVE-2022-0986
- EPSS 0.87%
- Veröffentlicht 16.03.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:48
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.