Vulnerabilities in hestiacp
18 resultsCVE-2022-2550CRITICALOS Command Injection in hestiacp/hestiacpEPSS 48.3%CVE-2022-1509CRITICALCommand Injection Vulnerability in hestiacp/hestiacpEPSS 4.5%CVE-2025-30007HIGHHestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record ManagementEPSS 3.2%CVE-2026-43633CRITICALHestiaCP 1.9.0-1.9.4 Deserialization RCE via Web TerminalEPSS 1.5%CVE-2022-2636HIGHCode Injection in hestiacp/hestiacpEPSS 1.3%CVE-2023-3479MEDIUMCross-site Scripting (XSS) - Reflected in hestiacp/hestiacpEPSS 1.3%CVE-2022-2626CRITICALIncorrect Privilege Assignment in hestiacp/hestiacpEPSS 1.3%CVE-2021-3797MEDIUMUse of Wrong Operator in String Comparison in hestiacp/hestiacpEPSS 1.1%CVE-2022-0838MEDIUMCross-site Scripting (XSS) - Reflected in hestiacp/hestiacpEPSS 1.1%CVE-2022-0752LOWCross-site Scripting (XSS) - Generic in hestiacp/hestiacpEPSS 1.0%CVE-2022-0986LOWReflected Cross-site Scripting (XSS) Vulnerability in hestiacp/hestiacpEPSS 0.9%CVE-2022-0753LOWCross-site Scripting (XSS) - Reflected in hestiacp/hestiacpEPSS 0.8%CVE-2023-5084LOWCross-site Scripting (XSS) - Reflected in hestiacp/hestiacpEPSS 0.5%CVE-2023-4517LOWCross-site Scripting (XSS) - Stored in hestiacp/hestiacpEPSS 0.4%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-43634HIGHHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP HeaderEPSS 0.4%CVE-2025-30008MEDIUMHestiaCP < 1.9.5 Stored XSS via DNS Record Management InterfaceEPSS 0.3%CVE-2023-5839HIGHPrivilege Chaining in hestiacp/hestiacpEPSS 0.3%