VYPR

Vendor CVEs

Webmin

All CVEs

121 total · sorted by risk
  • CVE-2023-41160MedSep 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the key name field while adding an authorized key.

  • CVE-2023-41159MedSep 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML by editing the forward file manually.

  • CVE-2023-41156MedSep 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the save to new folder named field while creating a new filter.

  • CVE-2023-41158MedSep 13, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program.

  • CVE-2023-41155MedSep 13, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the forward to field while creating a mail forwarding rule.

  • CVE-2023-41154MedSep 13, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the value field parameter while creating a new environment variable.

  • CVE-2023-41152MedSep 13, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the handle program field while creating a new MIME type program.

  • CVE-2023-41161MedSep 7, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the key comment to different pages such as public key details, Export key, sign key, send to key server page, and fetch from key server…

  • CVE-2023-41153MedAug 29, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via options for the host value while editing the host options.

  • CVE-2023-38311MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System Logs Viewer functionality. The vulnerability allows an attacker to store a malicious payload in the configuration field, triggering the execution of the…

  • CVE-2023-38310MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configuration settings of the system logs functionality. The vulnerability allows an attacker to store an XSS payload in the configuration settings of specific log…

  • CVE-2023-38307MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality. The vulnerability occurs when an authenticated user adds a new user and inserts an XSS payload into the user's real name.

  • CVE-2023-38304MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allowing an attacker to store a malicious payload in the Group Name field when creating a new group.

  • CVE-2023-38303MedJul 31, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through the Users and Group's real name parameter.

  • CVE-2020-8820MedOct 12, 2020
    risk 0.35cvss 5.4epss 0.01

    An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed.

  • CVE-2026-49102MedMay 27, 2026
    risk 0.33cvss 6.1epss 0.00

    Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

  • CVE-2023-52046MedJan 25, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.

  • CVE-2023-43309MedSep 21, 2023
    risk 0.31cvss 4.8epss 0.00

    There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.

  • CVE-2017-17089MedDec 30, 2017
    risk 0.31cvss 4.8epss 0.01

    custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

  • CVE-2026-22678MedMay 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by…

  • CVE-2026-56022MedJun 18, 2026
    risk 0.27cvss 5.3epss 0.01

    Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.

  • CVE-2026-56021MedJun 18, 2026
    risk 0.27cvss 5.3epss 0.00

    Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

  • CVE-2024-36452LowJul 10, 2024
    risk 0.20cvss 3.1epss 0.00

    Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred,…

  • CVE-2022-36446CriJul 25, 2022
    risk 0.11cvss 9.8epss 0.96

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

  • CVE-2022-0824HigMar 2, 2022
    risk 0.11cvss 8.8epss 0.97

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2006-3392Jul 6, 2006
    risk 0.09cvss epss 0.78

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed…

  • CVE-2003-0101Mar 3, 2003
    risk 0.04cvss epss 0.15

    miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root…

  • CVE-2001-1196Dec 17, 2001
    risk 0.04cvss epss 0.10

    Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.

  • CVE-2024-12828HigDec 30, 2024
    risk 0.03cvss 8.8epss 0.33

    Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of…

  • CVE-2019-15642HigAug 26, 2019
    risk 0.03cvss 8.8epss 0.37

    rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is…

  • CVE-2002-2360Dec 31, 2002
    risk 0.03cvss epss 0.04

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

  • CVE-2002-1673Dec 31, 2002
    risk 0.03cvss epss 0.01

    The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name…

  • CVE-2012-2982Sep 11, 2012
    risk 0.01cvss epss 0.62

    file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

  • CVE-2005-3912Nov 30, 2005
    risk 0.01cvss epss 0.14

    Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string…

  • CVE-2026-42210MedJul 20, 2026
    risk 0.00cvss epss 0.00

    Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic…

  • CVE-2022-3844LowNov 2, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the file xterm/index.cgi. The manipulation leads to basic cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.003 is able to…

  • CVE-2022-30708HigMay 15, 2022
    risk 0.00cvss 8.8epss 0.04

    Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2015-1377Feb 10, 2015
    risk 0.00cvss epss 0.00

    The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file.

  • CVE-2014-3886Jul 20, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

  • CVE-2014-3885Jul 20, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

  • CVE-2014-3884Jul 20, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

  • CVE-2014-3883Jun 21, 2014
    risk 0.00cvss epss 0.01

    Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.

  • CVE-2014-3924May 30, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.

  • CVE-2014-0339Mar 16, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2012-4893Sep 11, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue…

  • CVE-2012-2983Sep 11, 2012
    risk 0.00cvss epss 0.20

    file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

  • CVE-2012-2981Sep 11, 2012
    risk 0.00cvss epss 0.02

    Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

  • CVE-2011-1937May 31, 2011
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.

  • CVE-2009-4568Jan 5, 2010
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.