Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Awstats

First CVE: Jan 18, 2005Active for: 22 yearsTotal CVEs: 26
46.4
VTI Score
High

Awstats is a widely deployed open-source web analytics and log-analysis tool whose single-product footprint belies significant reach across hosting providers, content management systems, and web servers. Vulnerabilities affecting the product skew toward moderate severity and frequently acquire public exploit code, consistent with the tool's web-facing role and its exposure to direct user input through log parsing and report generation. The recurring weakness classes center on input-handling failures—path traversal, code injection, cross-site scripting, and improper input validation—reflecting the demands of safely processing and rendering log data from untrusted sources without sanitization. Defenders should treat Awstats instances, particularly those exposed to the internet or accepting user-controlled log input, as requiring close patch monitoring and input-filtering controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Awstats over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2005
21 years ago
Most Recent CVE
Mar 20, 2026
126 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-0116HIGH
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
Jan 18, 20057.581NOYES
CVE-2006-2237MEDIUM
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.
May 8, 20065.162NOYES
CVE-2010-4367HIGH
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on
Dec 2, 20107.547NOYES
CVE-2020-29600CRITICAL
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this
Dec 7, 20209.831NONO
CVE-2017-1000501CRITICAL
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
Jan 3, 20189.831NONO
CVE-2005-0436HIGH
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
May 2, 20057.531NOYES
CVE-2009-5020MEDIUM
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vecto
Dec 2, 20105.828NOYES
CVE-2006-3682MEDIUM
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.
Jul 21, 20065.028NOYES
CVE-2025-63261HIGH
AWStats 8.0 is vulnerable to Command Injection via the open function
Mar 20, 20267.827NONO
CVE-2018-10245MEDIUM
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar iss
Apr 20, 20185.327NOYES
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
58%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.8%)
Network5 (19.2%)
Unknown20 (76.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (23.1%)
High0 (0.0%)
Unknown20 (76.9%)
User Interaction
None5 (19.2%)
Unknown20 (76.9%)
Required1 (3.8%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None5 (19.2%)
Unknown20 (76.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
7.7% of CVEs· 98th percentile
Nuclei
2 CVEs
7.7% of CVEs· 96th percentile
ExploitDB
9 CVEs
34.6% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Awstats.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Awstats — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Awstats's Products

View all 3 CNAs →

Top CWEs