Awstats is a widely deployed open-source web analytics and log-analysis tool whose single-product footprint belies significant reach across hosting providers, content management systems, and web servers. Vulnerabilities affecting the product skew toward moderate severity and frequently acquire public exploit code, consistent with the tool's web-facing role and its exposure to direct user input through log parsing and report generation. The recurring weakness classes center on input-handling failures—path traversal, code injection, cross-site scripting, and improper input validation—reflecting the demands of safely processing and rendering log data from untrusted sources without sanitization. Defenders should treat Awstats instances, particularly those exposed to the internet or accepting user-controlled log input, as requiring close patch monitoring and input-filtering controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Awstats over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0116HIGH AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl. | Jan 18, 2005 | 7.5 | 81 | NO | YES |
CVE-2006-2237MEDIUM The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter. | May 8, 2006 | 5.1 | 62 | NO | YES |
CVE-2010-4367HIGH awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on | Dec 2, 2010 | 7.5 | 47 | NO | YES |
CVE-2020-29600CRITICAL In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this | Dec 7, 2020 | 9.8 | 31 | NO | NO |
CVE-2017-1000501CRITICAL Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution. | Jan 3, 2018 | 9.8 | 31 | NO | NO |
CVE-2005-0436HIGH Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter. | May 2, 2005 | 7.5 | 31 | NO | YES |
CVE-2009-5020MEDIUM Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vecto | Dec 2, 2010 | 5.8 | 28 | NO | YES |
CVE-2006-3682MEDIUM awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters. | Jul 21, 2006 | 5.0 | 28 | NO | YES |
CVE-2025-63261HIGH AWStats 8.0 is vulnerable to Command Injection via the open function | Mar 20, 2026 | 7.8 | 27 | NO | NO |
CVE-2018-10245MEDIUM A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar iss | Apr 20, 2018 | 5.3 | 27 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Awstats.
Media articles that mention a CVE ID that affects a product developed by Awstats — matched by CVE ID, not by vendor name.