VYPR

Webmin

by Webmin

Source repositories

CVEs (105)

  • CVE-2023-40982MedSep 15, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter.

  • CVE-2023-40986MedSep 15, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field.

  • CVE-2023-40985MedSep 15, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's…

  • CVE-2023-40984MedSep 15, 2023
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.

  • CVE-2023-41155MedSep 13, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the forward to field while creating a mail forwarding rule.

  • CVE-2023-38311MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System Logs Viewer functionality. The vulnerability allows an attacker to store a malicious payload in the configuration field, triggering the execution of the…

  • CVE-2023-38310MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configuration settings of the system logs functionality. The vulnerability allows an attacker to store an XSS payload in the configuration settings of specific log…

  • CVE-2023-38307MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality. The vulnerability occurs when an authenticated user adds a new user and inserts an XSS payload into the user's real name.

  • CVE-2023-38304MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allowing an attacker to store a malicious payload in the Group Name field when creating a new group.

  • CVE-2023-38303MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through the Users and Group's real name parameter.

  • CVE-2020-8820MedOct 12, 2020
    risk 0.35cvss 5.4epss 0.01

    An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed.

  • CVE-2026-49102MedMay 27, 2026
    risk 0.33cvss 6.1epss 0.00

    Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

  • CVE-2023-52046MedJan 25, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.

  • CVE-2023-43309MedSep 21, 2023
    risk 0.31cvss 4.8epss 0.00

    There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.

  • CVE-2017-17089MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.01

    custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

  • CVE-2026-22678MedMay 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by…

  • CVE-2026-56022MedJun 18, 2026
    risk 0.27cvss 5.3epss 0.01

    Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.

  • CVE-2026-56021MedJun 18, 2026
    risk 0.27cvss 5.3epss 0.00

    Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

  • CVE-2024-36452LowJul 10, 2024
    risk 0.20cvss 3.1epss 0.00

    Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred,…

  • CVE-2022-36446CriJul 25, 2022
    risk 0.11cvss 9.8epss 0.96

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

Page 3 of 6