Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Usermin

First CVE: Aug 12, 2002Active for: 24 yearsTotal CVEs: 14
42.8
VTI Score
High

Usermin is a single, modestly represented web-based email and file-management interface for system users, deployed in hosting and Unix-administration environments where it provides direct access to user mailboxes and home directories. Its vulnerability profile centers on web-application input-handling issues—principally cross-site scripting and cross-site request forgery—alongside broader categorization placeholders, and these flaws frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Usermin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Apr 28, 2025
452 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-3392MEDIUM
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..
Jul 6, 20065.083NOYES
CVE-2003-0101HIGH
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded string
Mar 3, 200310.044NOYES
CVE-2015-2079HIGH
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
Apr 28, 20258.826NONO
CVE-2005-1177HIGH
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
May 2, 200510.025NONO
CVE-2004-1468HIGH
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.
Dec 31, 20047.525NONO
CVE-2005-3042HIGH
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via
Sep 22, 20057.520NONO
CVE-2002-0757HIGH
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control chara
Aug 12, 20027.520NONO
CVE-2006-4542MEDIUM
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read C
Sep 5, 20066.819NONO
CVE-2002-0756HIGH
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly stea
Aug 12, 20027.519NONO
CVE-2004-0588MEDIUM
Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.
Aug 6, 20046.818NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
36%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (7.1%)
Unknown13 (92.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.1%)
High0 (0.0%)
Unknown13 (92.9%)
User Interaction
None1 (7.1%)
Unknown13 (92.9%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (92.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 98th percentile
Nuclei
1 CVE
7.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Usermin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Usermin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Usermin's Products

View all 2 CNAs →

Top CWEs