Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

hestiacp — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting hestiacp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HestiaCP serves as a web hosting control panel designed to simplify server management for web hosting providers and developers. Historically, the platform has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, with 13 CVEs documented to date. Notable security characteristics include its open-source nature and frequent updates, though past incidents have demonstrated that misconfigurations or unpatched installations could lead to complete server compromise. The platform's widespread adoption in shared hosting environments makes it a target for automated attacks, emphasizing the need for timely patching and hardening of default configurations.

Top products by hestiacp: hestiacp/hestiacp
CVE IDTitleCVSSSeverityPublished
CVE-2023-5839 Privilege Chaining in hestiacp/hestiacp — hestiacp/hestiacpCWE-268 8.8 -2023-10-29
CVE-2023-4517 Cross-site Scripting (XSS) - Stored in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 5.4 -2023-10-13
CVE-2023-5084 Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 3.9 Low2023-09-20
CVE-2023-3479 Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 6.1 -2023-06-30
CVE-2022-2636 Code Injection in hestiacp/hestiacp — hestiacp/hestiacpCWE-94 8.5 High2022-08-05
CVE-2022-2626 Incorrect Privilege Assignment in hestiacp/hestiacp — hestiacp/hestiacpCWE-266 6.5 -2022-08-05
CVE-2022-2550 OS Command Injection in hestiacp/hestiacp — hestiacp/hestiacpCWE-78 9.8 -2022-07-27
CVE-2022-1509 Command Injection Vulnerability in hestiacp/hestiacp — hestiacp/hestiacpCWE-77 9.9 Critical2022-04-28
CVE-2022-0986 Reflected Cross-site Scripting (XSS) Vulnerability in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 6.1 -2022-03-16
CVE-2022-0752 Cross-site Scripting (XSS) - Generic in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 5.4 -2022-03-04
CVE-2022-0838 Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 6.1 -2022-03-04
CVE-2022-0753 Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp — hestiacp/hestiacpCWE-79 6.1 -2022-03-03
CVE-2021-3797 Use of Wrong Operator in String Comparison in hestiacp/hestiacp — hestiacp/hestiacpCWE-597 9.8 -2021-09-15

This page lists every published CVE security advisory associated with hestiacp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.