CVE-2015-2861: Vestacp Vesta Control Panel

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.

Affected products

  • Vestacp Vesta Control Panel: up to and including 0.9.8-12

Published 2015-06-18. Last modified 2026-06-17.