Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hestiacp

First CVE: Mar 25, 2020Active for: 6 yearsTotal CVEs: 19
43.3
VTI Score
High

Hestiacp is a web hosting control panel that manages server administration and hosting provisioning, operating in a concentrated product footprint with modest overall vulnerability volume but elevated prominence within the hosting management software category. Its vulnerability profile clusters around input-handling and code-generation weaknesses characteristic of web-facing administrative interfaces, including cross-site scripting, command injection, and code injection conditions that reflect the panel's role in accepting and processing user-supplied configuration and administrative commands. Defenders managing hosting infrastructure should track this vendor's updates for the control panel specifically; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hestiacp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2020
6 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2550HIGH
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
Jul 27, 20228.853NONO
CVE-2025-30007HIGH
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting
Jul 10, 20268.840NONO
CVE-2023-3479MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
Jun 30, 20236.130NOYES
CVE-2021-3797CRITICAL
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
Sep 15, 20219.830NONO
CVE-2022-1509HIGH
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root c
Apr 28, 20228.829NONO
CVE-2022-2636HIGH
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Aug 5, 20228.828NONO
CVE-2025-30008MEDIUM
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a do
Jul 10, 20265.426NONO
CVE-2021-30070HIGH
An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being tran
Aug 18, 20227.525NONO
CVE-2022-2626HIGH
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Aug 5, 20227.224NONO
CVE-2023-5839HIGH
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
Oct 29, 20237.822NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
58%
37%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (47.4%)
Unknown0 (0.0%)
Required10 (52.6%)
Privileges Required
Low8 (42.1%)
High1 (5.3%)
None10 (52.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hestiacp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hestiacp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hestiacp's Products

View all 3 CNAs →

Top CWEs