← Vulnerability feed

Vulnerability record · CVE-2018-18547 · published 24 October 2018

CVE-2018-18547: Vestacp control panel cross-site scripting vulnerability

Vestacp · Control Panel

Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.

6.1 CVSS 3.0 Medium EPSS 1.1% · top 36.9% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-12791Vestacp control panel path traversal vulnerabilityA directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular regist…EPSS 6.5%8.8CVE-2019-12792Vestacp control panel os command injection vulnerabilityA command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered us…EPSS 4.9%8.8CVE-2015-4117Vestacp control panel os command injection vulnerabilityVesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter …EPSS 11%7.8CVE-2022-3967Vestacp control panel vulnerabilityA vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the …EPSS 0.23%7.8CVE-2021-30463Vestacp control panel link following vulnerabilityVestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY va…EPSS 0.50%7.2CVE-2021-46850Vestacp control panel argument injection vulnerabilitymyVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote adm…EPSS 5.4%6.5CVE-2020-10966Hestiacp control panel vulnerabilityIn the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account…EPSS 1.9%6.1CVE-2019-9841Vestacp control panel cross-site scripting vulnerabilityVesta Control Panel 0.9.8-23 allows XSS via a crafted URL.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2018-18547), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.