VYPR

Webmin

by Webmin

Source repositories

CVEs (105)

  • CVE-2019-15107CriKEVAug 16, 2019
    risk 0.93cvss 9.8epss 1.00

    An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

  • CVE-2021-31761CriApr 25, 2021
    risk 0.68cvss 9.6epss 0.34

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

  • CVE-2019-12840HigJun 15, 2019
    risk 0.66cvss 8.8epss 0.78

    In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.

  • CVE-2018-8712CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to…

  • CVE-2021-32157CriApr 11, 2022
    risk 0.63cvss 9.6epss 0.04

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2020-35606HigDec 21, 2020
    risk 0.62cvss 8.8epss 0.28

    Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

  • CVE-2021-31762HigApr 25, 2021
    risk 0.61cvss 8.8epss 0.09

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

  • CVE-2017-15645HigOct 19, 2017
    risk 0.60cvss 8.8epss 0.03

    CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.

  • CVE-2017-15644HigOct 19, 2017
    risk 0.60cvss 8.6epss 0.09

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

  • CVE-2021-31760HigApr 25, 2021
    risk 0.58cvss 8.8epss 0.08

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.

  • CVE-2024-36451HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a…

  • CVE-2021-32162HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.03

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

  • CVE-2021-32159HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

  • CVE-2021-32156HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2020-35769CriDec 29, 2020
    risk 0.57cvss 9.8epss 0.02

    miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

  • CVE-2019-9624HigMar 7, 2019
    risk 0.56cvss 7.8epss 0.24

    Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.

  • CVE-2025-67738HigDec 11, 2025
    risk 0.55cvss 8.5epss 0.00

    squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"…

  • CVE-2026-49103CriMay 27, 2026
    risk 0.54cvss epss 0.00

    Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

  • CVE-2024-45692HigSep 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

  • CVE-2026-56020HigJun 18, 2026
    risk 0.46cvss 8.1epss 0.01

    The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.

Page 1 of 6