Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-30008

HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record value field rendered into the data-sort-value HTML attribute in list_dns_rec.php, allowing the payload to execute in the browser of any user who views the DNS record list, including administrators.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.9%
CVSS Severity
CVSS v3 Score 4.6
Products affected by CVE-2025-30008


Contact Us

Shodan ® - All rights reserved