Vendor CVEs
Webmin
All CVEs
121 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15107 | Cri | 0.93 | 9.8 | 1.00 | KEV | Aug 16, 2019 | An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | |
| CVE-2021-31761 | Cri | 0.68 | 9.6 | 0.34 | Apr 25, 2021 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | ||
| CVE-2019-12840 | Hig | 0.66 | 8.8 | 0.78 | Jun 15, 2019 | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi. | ||
| CVE-2015-2079 | Cri | 0.64 | 9.9 | 0.01 | Apr 28, 2025 | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open. | ||
| CVE-2018-8712 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2018 | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to… | ||
| CVE-2021-32157 | Cri | 0.63 | 9.6 | 0.04 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2020-35606 | Hig | 0.62 | 8.8 | 0.28 | Dec 21, 2020 | Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840. | ||
| CVE-2021-31762 | Hig | 0.61 | 8.8 | 0.09 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. | ||
| CVE-2017-15645 | Hig | 0.60 | 8.8 | 0.03 | Oct 19, 2017 | CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands. | ||
| CVE-2017-15644 | Hig | 0.60 | 8.6 | 0.09 | Oct 19, 2017 | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. | ||
| CVE-2021-31760 | Hig | 0.58 | 8.8 | 0.08 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature. | ||
| CVE-2024-36451 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2024 | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a… | ||
| CVE-2022-35132 | Hig | 0.57 | 8.8 | 0.03 | Oct 25, 2022 | Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module. | ||
| CVE-2021-32162 | Hig | 0.57 | 8.8 | 0.03 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. | ||
| CVE-2021-32159 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2021-32156 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2020-35769 | Cri | 0.57 | 9.8 | 0.02 | Dec 29, 2020 | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. | ||
| CVE-2019-9624 | Hig | 0.56 | 7.8 | 0.24 | Mar 7, 2019 | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI. | ||
| CVE-2025-67738 | Hig | 0.55 | 8.5 | 0.00 | Dec 11, 2025 | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"… | ||
| CVE-2026-49103 | Cri | 0.54 | — | 0.00 | May 27, 2026 | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi. | ||
| CVE-2024-45692 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2024 | Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. | ||
| CVE-2026-56020 | Hig | 0.46 | 8.1 | 0.01 | Jun 18, 2026 | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202. | ||
| CVE-2025-61541 | Hig | 0.46 | 7.1 | 0.00 | Oct 16, 2025 | Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain… | ||
| CVE-2017-15646 | Med | 0.43 | 6.1 | 0.05 | Oct 19, 2017 | Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then… | ||
| CVE-2020-8821 | Med | 0.42 | 5.4 | 0.80 | Oct 12, 2020 | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered… | ||
| CVE-2019-15641 | Med | 0.42 | 6.5 | 0.01 | Aug 26, 2019 | xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi. | ||
| CVE-2024-36453 | Med | 0.40 | 6.1 | 0.00 | Jul 10, 2024 | Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the… | ||
| CVE-2023-40983 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2023 | A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file. | ||
| CVE-2023-41162 | Med | 0.40 | 6.1 | 0.00 | Sep 13, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the file mask field while searching under the tools drop down. | ||
| CVE-2023-41163 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down. | ||
| CVE-2023-38309 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in… | ||
| CVE-2023-38308 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the… | ||
| CVE-2023-38306 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a… | ||
| CVE-2023-38305 | Med | 0.40 | 6.1 | 0.01 | Jul 31, 2023 | An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within… | ||
| CVE-2022-36880 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2022 | The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message. | ||
| CVE-2021-32161 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature. | ||
| CVE-2021-32160 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature. | ||
| CVE-2021-32158 | Med | 0.40 | 6.1 | 0.02 | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2020-12670 | Med | 0.40 | 6.1 | 0.01 | Oct 12, 2020 | XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input… | ||
| CVE-2017-9313 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2017 | Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these… | ||
| CVE-2017-2106 | Med | 0.40 | 6.1 | 0.02 | Apr 28, 2017 | Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2016-4897 | Med | 0.40 | 6.1 | 0.01 | Apr 12, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. | ||
| CVE-2024-44762 | Med | 0.38 | 5.3 | 0.03 | Oct 16, 2024 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. | ||
| CVE-2018-19191 | Med | 0.38 | 5.4 | 0.39 | Mar 21, 2019 | Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter. | ||
| CVE-2024-36450 | Med | 0.35 | 5.4 | 0.00 | Jul 10, 2024 | Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be… | ||
| CVE-2023-41157 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab. | ||
| CVE-2023-40982 | Med | 0.35 | 5.4 | 0.00 | Sep 15, 2023 | A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter. | ||
| CVE-2023-40986 | Med | 0.35 | 5.4 | 0.00 | Sep 15, 2023 | A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field. | ||
| CVE-2023-40985 | Med | 0.35 | 5.4 | 0.00 | Sep 15, 2023 | An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's… | ||
| CVE-2023-40984 | Med | 0.35 | 5.4 | 0.00 | Sep 15, 2023 | A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file. |
- risk 0.93cvss 9.8epss 1.00
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
- risk 0.68cvss 9.6epss 0.34
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.
- risk 0.66cvss 8.8epss 0.78
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
- risk 0.64cvss 9.9epss 0.01
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to…
- risk 0.63cvss 9.6epss 0.04
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.62cvss 8.8epss 0.28
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
- risk 0.61cvss 8.8epss 0.09
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
- risk 0.60cvss 8.8epss 0.03
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
- risk 0.60cvss 8.6epss 0.09
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
- risk 0.58cvss 8.8epss 0.08
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.
- risk 0.57cvss 8.8epss 0.01
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a…
- risk 0.57cvss 8.8epss 0.03
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
- risk 0.57cvss 8.8epss 0.03
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
- risk 0.57cvss 8.8epss 0.02
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.57cvss 8.8epss 0.02
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.57cvss 9.8epss 0.02
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
- risk 0.56cvss 7.8epss 0.24
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
- risk 0.55cvss 8.5epss 0.00
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"…
- risk 0.54cvss —epss 0.00
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
- risk 0.49cvss 7.5epss 0.01
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
- risk 0.46cvss 8.1epss 0.01
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.
- risk 0.46cvss 7.1epss 0.00
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain…
- risk 0.43cvss 6.1epss 0.05
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then…
- risk 0.42cvss 5.4epss 0.80
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered…
- risk 0.42cvss 6.5epss 0.01
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the…
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.
- risk 0.40cvss 6.1epss 0.00
A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the file mask field while searching under the tools drop down.
- risk 0.40cvss 6.1epss 0.00
A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within…
- risk 0.40cvss 6.1epss 0.01
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.40cvss 6.1epss 0.01
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input…
- risk 0.40cvss 6.1epss 0.01
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these…
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.
- risk 0.38cvss 5.3epss 0.03
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
- risk 0.38cvss 5.4epss 0.39
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be…
- risk 0.35cvss 5.4epss 0.00
Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's…
- risk 0.35cvss 5.4epss 0.00
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.
Page 1 of 3