Webmin
by Webmin
Source repositories
CVEs (105)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-61541 | Hig | 0.46 | 7.1 | 0.00 | Oct 16, 2025 | Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain… | ||
| CVE-2017-15646 | Med | 0.43 | 6.1 | 0.05 | Oct 19, 2017 | Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then… | ||
| CVE-2020-8821 | Med | 0.42 | 5.4 | 0.80 | Oct 12, 2020 | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered… | ||
| CVE-2019-15641 | Med | 0.42 | 6.5 | 0.01 | Aug 26, 2019 | xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi. | ||
| CVE-2024-36453 | Med | 0.40 | 6.1 | 0.00 | Jul 10, 2024 | Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the… | ||
| CVE-2023-40983 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2023 | A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file. | ||
| CVE-2023-41163 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down. | ||
| CVE-2023-38309 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in… | ||
| CVE-2023-38308 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the… | ||
| CVE-2023-38306 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a… | ||
| CVE-2023-38305 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within… | ||
| CVE-2022-36880 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2022 | The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message. | ||
| CVE-2021-32161 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature. | ||
| CVE-2021-32160 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature. | ||
| CVE-2021-32158 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2020-12670 | Med | 0.40 | 6.1 | 0.01 | Oct 12, 2020 | XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input… | ||
| CVE-2017-9313 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2017 | Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these… | ||
| CVE-2017-2106 | Med | 0.40 | 6.1 | 0.02 | Apr 28, 2017 | Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2018-19191 | Med | 0.38 | 5.4 | 0.39 | Mar 21, 2019 | Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter. | ||
| CVE-2024-36450 | Med | 0.35 | 5.4 | 0.00 | Jul 10, 2024 | Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be… |
- risk 0.46cvss 7.1epss 0.00
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain…
- risk 0.43cvss 6.1epss 0.05
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then…
- risk 0.42cvss 5.4epss 0.80
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered…
- risk 0.42cvss 6.5epss 0.01
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the…
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.
- risk 0.40cvss 6.1epss 0.00
A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within…
- risk 0.40cvss 6.1epss 0.01
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.40cvss 6.1epss 0.01
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input…
- risk 0.40cvss 6.1epss 0.01
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these…
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.38cvss 5.4epss 0.39
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be…
Page 2 of 6