Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-56021 Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern. Webmin 1.290+ Fix from $1,6002026-06-18 MEDIUM 5.3 CVE-2026-56022 Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional … Webmin 2.640+ Fix from $1,6002026-06-18 MEDIUM 5.4 CVE-2026-22678 Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status modu… Webmin 2.641+ Fix from $1,6002026-05-21 HIGH 7.1 CVE-2025-61541 Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is construc… Webmin No fix yet Fix from $1,9502025-10-16 HIGH 8.8 CVE-2015-2079 Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argume… Usermin 1.660+ Fix from $1,9502025-04-28 HIGH 8.8 CVE-2024-12828EPSS 33% Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… Webmin Patch available Fix from $1,9502024-12-30 MEDIUM 5.3 CVE-2024-44762 A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. Usermin No fix yet Fix from $1,6002024-10-16 HIGH 8.8 CVE-2024-36451 Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability i… Webmin 2.003+ Fix from $1,9502024-07-10 MEDIUM 6.1 CVE-2024-36453 Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnera… Usermin 1.820 / 1.970+ Fix from $1,6002024-07-10 MEDIUM 5.4 CVE-2024-36450 Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script m… Webmin 1.910+ Fix from $1,6002024-07-10 MEDIUM 5.4 CVE-2023-41157 Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the fol… Usermin Mitigation only Fix from $1,6002023-09-16 MEDIUM 6.1 CVE-2023-40983 A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via … Webmin No fix yet Fix from $1,6002023-09-15 MEDIUM 5.4 CVE-2023-40982 A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in… Webmin No fix yet Fix from $1,6002023-09-15 MEDIUM 5.4 CVE-2023-40984 A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via … Webmin No fix yet Fix from $1,6002023-09-15 MEDIUM 5.4 CVE-2023-40985 An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By … Webmin No fix yet Fix from $1,6002023-09-15 MEDIUM 5.4 CVE-2023-40986 A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sr… Webmin No fix yet Fix from $1,6002023-09-15 MEDIUM 5.4 CVE-2023-41156 A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web… Usermin Mitigation only Fix from $1,6002023-09-14 MEDIUM 5.4 CVE-2023-41159 A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote attackers to inject arbitrary … Usermin Mitigation only Fix from $1,6002023-09-14 MEDIUM 5.4 CVE-2023-41160 A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web scrip… Usermin No fix yet Fix from $1,6002023-09-14 MEDIUM 6.1 CVE-2023-41162 A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script … Usermin Mitigation only Fix from $1,6002023-09-13 MEDIUM 5.4 CVE-2023-41152 A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web scri… Usermin Mitigation only Fix from $1,6002023-09-13 MEDIUM 5.4 CVE-2023-41154 A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web scr… Usermin Mitigation only Fix from $1,6002023-09-13 MEDIUM 5.4 CVE-2023-41155 A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows remote attackers to injec… Usermin Mitigation only Fix from $1,6002023-09-13 MEDIUM 5.4 CVE-2023-41158 A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web scri… Usermin Mitigation only Fix from $1,6002023-09-13 MEDIUM 5.4 CVE-2023-41161 Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the key… Usermin Mitigation only Fix from $1,6002023-09-07 MEDIUM 6.1 CVE-2023-41163 A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script … Webmin Mitigation only Fix from $1,6002023-08-30 MEDIUM 5.4 CVE-2023-41153 A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web scrip… Usermin Mitigation only Fix from $1,6002023-08-29 MEDIUM 6.1 CVE-2023-38305 An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By prov… Webmin No fix yet Fix from $1,6002023-07-31 MEDIUM 6.1 CVE-2023-38306 An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally,… Webmin No fix yet Fix from $1,6002023-07-31 MEDIUM 6.1 CVE-2023-38308 An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling thi… Webmin No fix yet Fix from $1,6002023-07-31