Webmin
Webmin is a web-based server management control panel for Unix-like systems. Webmin allows the user to configure operating system internals, such as users, disk quotas, services and configuration files, as well as modify and control open-source apps, such as BIND, Apache HTTP Server, PHP, and MySQL.
Products
12- 105 CVEs
- 31 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
121| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15107 | Cri | 0.93 | 9.8 | 1.00 | KEV | Aug 16, 2019 | An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | |
| CVE-2021-31761 | Cri | 0.68 | 9.6 | 0.34 | Apr 25, 2021 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | ||
| CVE-2019-12840 | Hig | 0.66 | 8.8 | 0.78 | Jun 15, 2019 | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi. | ||
| CVE-2015-2079 | Cri | 0.64 | 9.9 | 0.01 | Apr 28, 2025 | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open. | ||
| CVE-2018-8712 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2018 | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to… | ||
| CVE-2021-32157 | Cri | 0.63 | 9.6 | 0.04 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2020-35606 | Hig | 0.62 | 8.8 | 0.28 | Dec 21, 2020 | Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840. | ||
| CVE-2021-31762 | Hig | 0.61 | 8.8 | 0.09 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. | ||
| CVE-2017-15645 | Hig | 0.60 | 8.8 | 0.03 | Oct 19, 2017 | CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands. | ||
| CVE-2017-15644 | Hig | 0.60 | 8.6 | 0.09 | Oct 19, 2017 | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. | ||
| CVE-2021-31760 | Hig | 0.58 | 8.8 | 0.08 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature. | ||
| CVE-2024-36451 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2024 | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a… | ||
| CVE-2022-35132 | Hig | 0.57 | 8.8 | 0.03 | Oct 25, 2022 | Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module. | ||
| CVE-2021-32162 | Hig | 0.57 | 8.8 | 0.03 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. | ||
| CVE-2021-32159 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2021-32156 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2020-35769 | Cri | 0.57 | 9.8 | 0.02 | Dec 29, 2020 | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. | ||
| CVE-2019-9624 | Hig | 0.56 | 7.8 | 0.24 | Mar 7, 2019 | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI. | ||
| CVE-2025-67738 | Hig | 0.55 | 8.5 | 0.00 | Dec 11, 2025 | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"… | ||
| CVE-2026-49103 | Cri | 0.54 | — | 0.00 | May 27, 2026 | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi. |
- risk 0.93cvss 9.8epss 1.00
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
- risk 0.68cvss 9.6epss 0.34
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.
- risk 0.66cvss 8.8epss 0.78
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
- risk 0.64cvss 9.9epss 0.01
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to…
- risk 0.63cvss 9.6epss 0.04
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.62cvss 8.8epss 0.28
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
- risk 0.61cvss 8.8epss 0.09
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
- risk 0.60cvss 8.8epss 0.03
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
- risk 0.60cvss 8.6epss 0.09
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
- risk 0.58cvss 8.8epss 0.08
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.
- risk 0.57cvss 8.8epss 0.01
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a…
- risk 0.57cvss 8.8epss 0.03
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
- risk 0.57cvss 8.8epss 0.03
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
- risk 0.57cvss 8.8epss 0.02
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.57cvss 8.8epss 0.02
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.57cvss 9.8epss 0.02
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
- risk 0.56cvss 7.8epss 0.24
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
- risk 0.55cvss 8.5epss 0.00
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"…
- risk 0.54cvss —epss 0.00
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.