Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vestacp

First CVE: Jun 18, 2015Active for: 11 yearsTotal CVEs: 24
51.4
VTI Score
TOP TARGET

Vestacp provides a control-panel platform for web hosting and server administration, and despite a narrow product portfolio, occupies a meaningful position among hosting infrastructure targets. Vulnerabilities affecting the vendor show a moderate tendency toward serious severity outcomes and frequently acquire public exploit code, reflecting the administrative scope and internet-facing nature of the control-panel interface. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, and CSRF—center on input handling and command construction in a web application managing privileged server operations, creating a consistent attack surface for both remote code execution and account compromise. Defenders should treat Vestacp instances as high-value targets for patching, particularly those exposed to untrusted networks, and should inventory deployment scope given the sensitive administrative functions the platform provides. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vestacp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2015
11 years ago
Most Recent CVE
Jan 21, 2026
184 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-10808HIGH
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on t
Mar 22, 20208.880NOYES
CVE-2021-28379HIGH
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
Mar 15, 20218.840NOYES
CVE-2015-4117HIGH
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
Feb 28, 20188.836NOYES
CVE-2021-43693CRITICAL
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
Nov 29, 20219.831NONO
CVE-2018-1000884CRITICAL
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vuln
Dec 20, 20189.830NONO
CVE-2019-12792HIGH
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
Aug 15, 20198.828NONO
CVE-2019-12791HIGH
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the pass
Aug 15, 20198.828NONO
CVE-2020-10786HIGH
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
Apr 21, 20208.827NONO
CVE-2022-3967HIGH
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The mani
Nov 13, 20227.826NONO
CVE-2021-46850HIGH
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute ar
Oct 24, 20227.226NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
38%
54%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (8.3%)
Network21 (87.5%)
Unknown1 (4.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High0 (0.0%)
Unknown1 (4.2%)
User Interaction
None14 (58.3%)
Unknown1 (4.2%)
Required9 (37.5%)
Privileges Required
Low9 (37.5%)
High2 (8.3%)
None12 (50.0%)
Unknown1 (4.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vestacp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vestacp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vestacp's Products

View all 4 CNAs →

Top CWEs