Cross-site scripting in Hestia Control Panel - #VU140559
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator context and gain access to administrator functions.
The vulnerability exists due to cross-site scripting in the SSL certificate handling functionality when processing crafted self-signed certificate data in site settings. A remote user can inject a crafted script through certificate fields to execute arbitrary JavaScript in an administrator context and gain access to administrator functions.
User interaction is required because an administrator must open the affected site settings page after logging in as the target user.