Hestiacp is a web hosting control panel that manages server administration and hosting provisioning, operating in a concentrated product footprint with modest overall vulnerability volume but elevated prominence within the hosting management software category. Its vulnerability profile clusters around input-handling and code-generation weaknesses characteristic of web-facing administrative interfaces, including cross-site scripting, command injection, and code injection conditions that reflect the panel's role in accepting and processing user-supplied configuration and administrative commands. Defenders managing hosting infrastructure should track this vendor's updates for the control panel specifically; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hestiacp over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2550HIGH OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. | Jul 27, 2022 | 8.8 | 53 | NO | NO |
CVE-2025-30007HIGH HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting | Jul 10, 2026 | 8.8 | 40 | NO | NO |
CVE-2023-3479MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. | Jun 30, 2023 | 6.1 | 30 | NO | YES |
CVE-2021-3797CRITICAL hestiacp is vulnerable to Use of Wrong Operator in String Comparison | Sep 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-1509HIGH Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root c | Apr 28, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-2636HIGH Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | Aug 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-30008MEDIUM HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a do | Jul 10, 2026 | 5.4 | 26 | NO | NO |
CVE-2021-30070HIGH An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being tran | Aug 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-2626HIGH Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | Aug 5, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-5839HIGH Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. | Oct 29, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hestiacp.
Media articles that mention a CVE ID that affects a product developed by Hestiacp — matched by CVE ID, not by vendor name.