Control Panel
Vendor:
First CVE: Feb 28, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 89% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Control Panel over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2018
8 years ago
Most Recent CVE
Nov 13, 2022
1,353 days ago
CVE Severity & Scoring
Control Panel10 CVEs
40%
60%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low5 (50.0%)
High1 (10.0%)
None4 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4117HIGH Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php. | Feb 28, 2018 | 8.8 | 36 | NO | YES |
CVE-2019-12792HIGH A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. | Aug 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-12791HIGH A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the pass | Aug 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-3967HIGH A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The mani | Nov 13, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-46850HIGH myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute ar | Oct 24, 2022 | 7.2 | 26 | NO | NO |
CVE-2021-30463HIGH VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /u | Apr 8, 2021 | 7.8 | 22 | NO | NO |
CVE-2019-9841MEDIUM Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. | Apr 19, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-18547MEDIUM Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parame | Oct 24, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-10686MEDIUM An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution vi | May 6, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-10966MEDIUM In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim re | Mar 25, 2020 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Control Panel
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.8-24 | 2 | 8.8 | 5.7% | 0 | 0 |
| 0.9.8-23 | 1 | 6.1 | 1.3% | 0 | 0 |
| 0.9.8-20 | 1 | 6.1 | 1.3% | 0 | 0 |