Known Vulnerabilities for Control Panel by Hestiacp
Listed below are 10 of the newest known vulnerabilities associated with "Control Panel" by "Hestiacp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84802 json | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveI... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84801 json | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84793 json | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field t... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84792 json | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82865 json | pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assign... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-78416 json | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code executi... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-72787 json | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names a... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-72785 json | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the v... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72782 json | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (v... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72781 json | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in... | Not Provided | 2026-08-11 | 2026-08-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hestiacp | Control Panel | 1.3.3 | |||
| Application | Hestiacp | Control Panel | 1.3.2 | |||
| Application | Hestiacp | Control Panel | 1.3.1 | |||
| Application | Hestiacp | Control Panel | 1.3.0 | |||
| Application | Hestiacp | Control Panel | 1.2.4 | |||
| Application | Hestiacp | Control Panel | 1.2.3 | |||
| Application | Hestiacp | Control Panel | 1.2.2 | |||
| Application | Hestiacp | Control Panel | 1.2.1 | |||
| Application | Hestiacp | Control Panel | 1.2.0 | |||
| Application | Hestiacp | Control Panel | 1.1.1 | |||
| Application | Hestiacp | Control Panel | 1.1.0 | |||
| Application | Hestiacp | Control Panel | 1.00.0-190618 | |||
| Application | Hestiacp | Control Panel | 1.0.6 | |||
| Application | Hestiacp | Control Panel | 1.0.5 | |||
| Application | Hestiacp | Control Panel | 1.0.4 | |||
| Application | Hestiacp | Control Panel | 1.0.3 | |||
| Application | Hestiacp | Control Panel | 1.0.1 | |||
| Application | Hestiacp | Control Panel | 0.9.8-28 | |||
| Application | Hestiacp | Control Panel | - |