Webmin records
112 published records for vendor webmin.
Researcher profile
- Entered KEV
- 1 · 0.9%
- Weaponized
- 6 · 5.4%
- Pre-auth RCE
- 11
- With a fix record
- 8.9%
- Median publish → KEV
- 953 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-284 Improper Access Control2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
The weakness classes this vendor ships most often: where to look.
CWEAll records
112 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-15107Weaponized | An issue was discovered in Webmin <=1.920.webmin · webmin · CWE-78 | Critical9.8 | KEV | 99.7% | Aug 15, 2019 |
68This week | CVE-2022-36446Weaponized | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Critical9.8 | — | 96.0% | Jul 25, 2022 |
64This week | CVE-2022-0824Weaponized | Improper Access Control to Remote Code Execution in webmin/webminwebmin · webmin · CWE-284 | High8.8 | — | 97.0% | Mar 2, 2022 |
58Plan | CVE-2019-12840Weaponized | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the datwebmin · webmin · CWE-78 | High8.8 | — | 77.8% | Jun 15, 2019 |
48Plan | CVE-2021-31761Proof of concept | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featurwebmin · webmin · CWE-79 | Critical9.6 | — | 33.6% | Apr 25, 2021 |
45Plan | CVE-2020-8821No exploit | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.webmin · webmin · CWE-79 | Medium5.4 | — | 80.2% | Oct 12, 2020 |
45Plan | CVE-2019-15642Proof of concept | rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an ewebmin · webmin · CWE-94 | High8.8 | — | 34.8% | Aug 26, 2019 |
45Plan | CVE-2024-12828Proof of concept | Webmin CGI Command Injection Remote Code Execution Vulnerabilitywebmin · webmin · CWE-78 | High8.8 | — | 33.5% | Dec 30, 2024 |
45Plan | CVE-2003-0101Proof of concept | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage usermin · usermin | Critical10.0 | — | 15.5% | Mar 3, 2003 |
43Plan | CVE-2006-3392Weaponized | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arusermin · usermin | Medium5.0 | — | 78.3% | Jul 6, 2006 |
43Plan | CVE-2020-35606Proof of concept | Arbitrary command execution can occur in Webmin through 1.962.webmin · webmin · CWE-78 | High8.8 | — | 28.0% | Dec 21, 2020 |
43Plan | CVE-2001-1196Proof of concept | Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in thwebmin · webmin | Critical10.0 | — | 9.8% | Dec 17, 2001 |
41Plan | CVE-2002-2201No exploit | The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacterwebmin · webmin | Critical10.0 | — | 3.3% | Dec 31, 2002 |
41Plan | CVE-2005-1177No exploit | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, wusermin · usermin | Critical10.0 | — | 1.8% | May 2, 2005 |
40Plan | CVE-2018-8712No exploit | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.webmin · webmin · CWE-22 | Critical9.8 | — | 1.8% | Mar 14, 2018 |
40Plan | CVE-2020-35769No exploit | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.webmin · webmin | Critical9.8 | — | 1.8% | Dec 29, 2020 |
39Monitor | CVE-2021-32157Proof of concept | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.webmin · webmin · CWE-79 | Critical9.6 | — | 4.0% | Apr 11, 2022 |
38Monitor | CVE-2019-9624Weaponized | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges towebmin · webmin · CWE-269 | High7.8 | — | 23.7% | Mar 7, 2019 |
38Monitor | CVE-2021-31762Proof of concept | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get awebmin · webmin · CWE-352 | High8.8 | — | 8.8% | Apr 25, 2021 |
38Monitor | CVE-2021-31760Proof of concept | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feawebmin · webmin · CWE-352 | High8.8 | — | 8.5% | Apr 25, 2021 |
38Monitor | CVE-2002-2360Proof of concept | The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arwebmin · webmin · CWE-264 | Critical9.3 | — | 3.6% | Dec 31, 2002 |
37Monitor | CVE-2017-15644Proof of concept | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80webmin · webmin · CWE-918 | High8.6 | — | 8.9% | Oct 19, 2017 |
37Monitor | CVE-2007-5066No exploit | Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URwebmin · webmin · CWE-20 | Critical9.0 | — | 2.4% | Sep 24, 2007 |
36Monitor | CVE-2022-30708No exploit | Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not createwebmin · webmin | High8.8 | — | 3.6% | May 14, 2022 |
36Monitor | CVE-2017-15645Proof of concept | CSRF exists in Webmin 1.850.webmin · webmin · CWE-352 | High8.8 | — | 3.2% | Oct 19, 2017 |
- CVE-2019-1510799Now
An issue was discovered in Webmin <=1.920.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%webmin · webminAug 15, 2019
- CVE-2022-3644668This week
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CriticalCVSS 9.8WeaponizedEPSS 96%webmin · webminJul 25, 2022
- CVE-2022-082464This week
Improper Access Control to Remote Code Execution in webmin/webmin
HighCVSS 8.8WeaponizedEPSS 97%webmin · webminMar 2, 2022
- CVE-2019-1284058Plan
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat
HighCVSS 8.8WeaponizedEPSS 78%webmin · webminJun 15, 2019
- CVE-2021-3176148Plan
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur
CriticalCVSS 9.6Proof of conceptEPSS 34%webmin · webminApr 25, 2021
- CVE-2020-882145Plan
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.
MediumCVSS 5.4No exploitEPSS 80%webmin · webminOct 12, 2020
- CVE-2019-1564245Plan
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e
HighCVSS 8.8Proof of conceptEPSS 35%webmin · webminAug 26, 2019
- CVE-2024-1282845Plan
Webmin CGI Command Injection Remote Code Execution Vulnerability
HighCVSS 8.8Proof of conceptEPSS 33%webmin · webminDec 30, 2024
- CVE-2003-010145Plan
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage
CriticalCVSS 10.0Proof of conceptEPSS 15%usermin · userminMar 3, 2003
- CVE-2006-339243Plan
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar
MediumCVSS 5.0WeaponizedEPSS 78%usermin · userminJul 6, 2006
- CVE-2020-3560643Plan
Arbitrary command execution can occur in Webmin through 1.962.
HighCVSS 8.8Proof of conceptEPSS 28%webmin · webminDec 21, 2020
- CVE-2001-119643Plan
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th
CriticalCVSS 10.0Proof of conceptEPSS 10%webmin · webminDec 17, 2001
- CVE-2002-220141Plan
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
CriticalCVSS 10.0No exploitEPSS 3%webmin · webminDec 31, 2002
- CVE-2005-117741Plan
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w
CriticalCVSS 10.0No exploitEPSS 2%usermin · userminMay 2, 2005
- CVE-2018-871240Plan
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.
CriticalCVSS 9.8No exploitEPSS 2%webmin · webminMar 14, 2018
- CVE-2020-3576940Plan
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
CriticalCVSS 9.8No exploitEPSS 2%webmin · webminDec 29, 2020
- CVE-2021-3215739Monitor
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CriticalCVSS 9.6Proof of conceptEPSS 4%webmin · webminApr 11, 2022
- CVE-2019-962438Monitor
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to
HighCVSS 7.8WeaponizedEPSS 24%webmin · webminMar 7, 2019
- CVE-2021-3176238Monitor
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a
HighCVSS 8.8Proof of conceptEPSS 9%webmin · webminApr 25, 2021
- CVE-2021-3176038Monitor
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea
HighCVSS 8.8Proof of conceptEPSS 8%webmin · webminApr 25, 2021
- CVE-2002-236038Monitor
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar
CriticalCVSS 9.3Proof of conceptEPSS 4%webmin · webminDec 31, 2002
- CVE-2017-1564437Monitor
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80
HighCVSS 8.6Proof of conceptEPSS 9%webmin · webminOct 19, 2017
- CVE-2007-506637Monitor
Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR
CriticalCVSS 9.0No exploitEPSS 2%webmin · webminSep 24, 2007
- CVE-2022-3070836Monitor
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create
HighCVSS 8.8No exploitEPSS 4%webmin · webminMay 14, 2022
- CVE-2017-1564536Monitor
CSRF exists in Webmin 1.850.
HighCVSS 8.8Proof of conceptEPSS 3%webmin · webminOct 19, 2017