CVE-2025-30008: medium-severity vulnerability in hestiacp
HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record value field rendered into the data-sort-value HTML attribute in list_dns_rec.php, allowing the payload to execute in the browser of any user who views the DNS record list, including administrators.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
hestiacp · hestiacpRelated CVEs — hestiacp
In the same product, most dangerous first.
CVE-2025-30007HIGHHestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record ManagementEPSS 3.2%CVE-2026-43633CRITICALHestiaCP 1.9.0-1.9.4 Deserialization RCE via Web TerminalEPSS 1.5%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-43634HIGHHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP HeaderEPSS 0.4%