Webmin

Vendor:

First CVE: May 2, 2005 · Active for 21 years

5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Sep 11, 2012
5,065 days ago

CVE Severity & Scoring

Webmin5 CVEs
All CVEs352,708 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) char
Sep 11, 20126.574NOYES
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary fi
Sep 11, 20125.035NOYES
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for
Sep 11, 20126.821NONO
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
Sep 11, 20126.020NONO
The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote
May 2, 20055.015NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
40.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Webmin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.58046.121.4%02
1.57046.121.4%02
1.56046.121.4%02
1.55046.121.4%02
1.53046.121.4%02
1.52046.121.4%02
1.51046.121.4%02
1.50046.121.4%02
1.48046.121.4%02
1.47046.121.4%02
1.45046.121.4%02
1.44046.121.4%02
1.43046.121.4%02
1.42046.121.4%02
1.41046.121.4%02
1.40046.121.4%02
1.39046.121.4%02
1.38046.121.4%02
1.37046.121.4%02
1.34046.121.4%02