Usermin is a single, modestly represented web-based email and file-management interface for system users, deployed in hosting and Unix-administration environments where it provides direct access to user mailboxes and home directories. Its vulnerability profile centers on web-application input-handling issues—principally cross-site scripting and cross-site request forgery—alongside broader categorization placeholders, and these flaws frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usermin over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3392MEDIUM Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using ".. | Jul 6, 2006 | 5.0 | 83 | NO | YES |
CVE-2003-0101HIGH miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded string | Mar 3, 2003 | 10.0 | 44 | NO | YES |
CVE-2015-2079HIGH Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open. | Apr 28, 2025 | 8.8 | 26 | NO | NO |
CVE-2005-1177HIGH Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact. | May 2, 2005 | 10.0 | 25 | NO | NO |
CVE-2004-1468HIGH The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message. | Dec 31, 2004 | 7.5 | 25 | NO | NO |
CVE-2005-3042HIGH miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via | Sep 22, 2005 | 7.5 | 20 | NO | NO |
CVE-2002-0757HIGH (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control chara | Aug 12, 2002 | 7.5 | 20 | NO | NO |
CVE-2006-4542MEDIUM Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read C | Sep 5, 2006 | 6.8 | 19 | NO | NO |
CVE-2002-0756HIGH Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly stea | Aug 12, 2002 | 7.5 | 19 | NO | NO |
CVE-2004-0588MEDIUM Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages. | Aug 6, 2004 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usermin.
Media articles that mention a CVE ID that affects a product developed by Usermin — matched by CVE ID, not by vendor name.