VYPR

Webmin

by Webmin

Source repositories

CVEs (105)

  • CVE-2025-61541HigOct 16, 2025
    risk 0.46cvss 7.1epss 0.00

    Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain…

  • CVE-2017-15646MedOct 19, 2017
    risk 0.43cvss 6.1epss 0.05

    Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then…

  • CVE-2020-8821MedOct 12, 2020
    risk 0.42cvss 5.4epss 0.80

    An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered…

  • CVE-2019-15641MedAug 26, 2019
    risk 0.42cvss 6.5epss 0.01

    xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.

  • CVE-2024-36453MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the…

  • CVE-2023-40983MedSep 15, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.

  • CVE-2023-41163MedAug 30, 2023
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.

  • CVE-2023-38309MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in…

  • CVE-2023-38308MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the…

  • CVE-2023-38306MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a…

  • CVE-2023-38305MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within…

  • CVE-2022-36880MedJul 27, 2022
    risk 0.40cvss 6.1epss 0.01

    The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.

  • CVE-2021-32161MedApr 11, 2022
    risk 0.40cvss 6.1epss 0.02

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.

  • CVE-2021-32160MedApr 11, 2022
    risk 0.40cvss 6.1epss 0.02

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.

  • CVE-2021-32158MedApr 11, 2022
    risk 0.40cvss 6.1epss 0.02

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

  • CVE-2020-12670MedOct 12, 2020
    risk 0.40cvss 6.1epss 0.01

    XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input…

  • CVE-2017-9313MedJul 4, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these…

  • CVE-2017-2106MedApr 28, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-19191MedMar 21, 2019
    risk 0.38cvss 5.4epss 0.39

    Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.

  • CVE-2024-36450MedJul 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be…

Page 2 of 6