PT-2026-57247 · Hestiacp · Hestiacp

·

CVE-2025-30008

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HestiaCP versions prior to 1.9.5
Description An authenticated low-privilege user can perform a stored cross-site scripting attack by creating a DNS record containing a double-quote followed by a script payload in the value field. The issue occurs because the application does not use the htmlspecialchars() function to encode the DNS record value when it is rendered within the data-sort-value HTML attribute in the 'list dns rec.php' endpoint. This allows the injected script to execute in the browser of any user who views the DNS record list, including those with administrator privileges.
Recommendations Update HestiaCP to version 1.9.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30008

Affected Products

Hestiacp