Known Vulnerabilities for products from Vestacp
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vestacp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-36305 json | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/uplo... | 6.1 - MEDIUM | 2022-07-19 | 2022-07-25 |
| CVE-2022-36304 json | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /we... | 6.1 - MEDIUM | 2022-07-19 | 2022-07-25 |
| CVE-2022-36303 json | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /w... | 6.1 - MEDIUM | 2022-07-19 | 2022-07-25 |
| CVE-2022-34025 json | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/uplo... | 6.1 - MEDIUM | 2022-07-19 | 2022-07-25 |
| CVE-2022-3967 json | A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the f... | 7.8 - HIGH | 2022-11-13 | 2023-11-07 |
| CVE-2021-46850 json | myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An auth... | 7.2 - HIGH | 2022-10-24 | 2023-08-08 |
| CVE-2021-43693 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2021-11-29 | 2021-11-30 |
| CVE-2021-30463 json | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. A... | 7.8 - HIGH | 2021-04-08 | 2021-04-14 |
| CVE-2021-30462 json | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require... | 7.2 - HIGH | 2021-04-08 | 2022-07-12 |
| CVE-2021-28379 json | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows upl... | 8.8 - HIGH | 2021-03-15 | 2021-03-19 |
| CVE-2020-10966 json | In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manip... | 6.5 - MEDIUM | 2020-03-25 | 2022-07-12 |
| CVE-2020-10808 json | Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The ... | 8.8 - HIGH | 2020-03-22 | 2023-02-03 |
| CVE-2020-10787 json | An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admi... | 8.8 - HIGH | 2020-04-21 | 2021-07-21 |
| CVE-2020-10786 json | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary command... | 8.8 - HIGH | 2020-04-21 | 2021-07-21 |
| CVE-2019-12792 json | A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate fr... | 8.8 - HIGH | 2019-08-15 | 2020-08-24 |
| CVE-2019-12791 json | A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to esca... | 8.8 - HIGH | 2019-08-15 | 2019-08-28 |
| CVE-2019-9859 json | Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in r... | 8.8 - HIGH | 2020-03-10 | 2020-03-20 |
| CVE-2019-9841 json | Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. | 6.1 - MEDIUM | 2019-04-19 | 2019-04-22 |
| CVE-2018-1000884 json | Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208... | 9.8 - CRITICAL | 2018-12-20 | 2020-08-24 |
| CVE-2018-18547 json | Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/... | 6.1 - MEDIUM | 2018-10-24 | 2018-12-04 |
Known software with vulnerabilities from Vestacp
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Vestacp | Control Panel | 0.9.7-13 |
| Application | Vestacp | Vesta Control Panel | 0.9.7-0 |