Control Panel

Vendor:

First CVE: Feb 28, 2018 · Active for 8 years

10
Total CVEs
More Total CVEs than 89% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Control Panel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2018
8 years ago
Most Recent CVE
Nov 13, 2022
1,353 days ago

CVE Severity & Scoring

Control Panel10 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low5 (50.0%)
High1 (10.0%)
None4 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
Feb 28, 20188.836NOYES
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
Aug 15, 20198.828NONO
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the pass
Aug 15, 20198.828NONO
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The mani
Nov 13, 20227.826NONO
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute ar
Oct 24, 20227.226NONO
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /u
Apr 8, 20217.822NONO
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
Apr 19, 20196.122NONO
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parame
Oct 24, 20186.121NONO
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution vi
May 6, 20186.121NONO
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim re
Mar 25, 20206.518NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Control Panel

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.8-2428.85.7%00
0.9.8-2316.11.3%00
0.9.8-2016.11.3%00