Vestacp provides a control-panel platform for web hosting and server administration, and despite a narrow product portfolio, occupies a meaningful position among hosting infrastructure targets. Vulnerabilities affecting the vendor show a moderate tendency toward serious severity outcomes and frequently acquire public exploit code, reflecting the administrative scope and internet-facing nature of the control-panel interface. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, and CSRF—center on input handling and command construction in a web application managing privileged server operations, creating a consistent attack surface for both remote code execution and account compromise. Defenders should treat Vestacp instances as high-value targets for patching, particularly those exposed to untrusted networks, and should inventory deployment scope given the sensitive administrative functions the platform provides. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vestacp over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10808HIGH Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on t | Mar 22, 2020 | 8.8 | 80 | NO | YES |
CVE-2021-28379HIGH web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. | Mar 15, 2021 | 8.8 | 40 | NO | YES |
CVE-2015-4117HIGH Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php. | Feb 28, 2018 | 8.8 | 36 | NO | YES |
CVE-2021-43693CRITICAL vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. | Nov 29, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-1000884CRITICAL Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vuln | Dec 20, 2018 | 9.8 | 30 | NO | NO |
CVE-2019-12792HIGH A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. | Aug 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-12791HIGH A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the pass | Aug 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-10786HIGH A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs. | Apr 21, 2020 | 8.8 | 27 | NO | NO |
CVE-2022-3967HIGH A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The mani | Nov 13, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-46850HIGH myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute ar | Oct 24, 2022 | 7.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vestacp.
Media articles that mention a CVE ID that affects a product developed by Vestacp — matched by CVE ID, not by vendor name.