CVE-2025-30008
Published Jul 10, 2026HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a d…
- evidence mentions
- 4
- Buzz score
- 22.6