Skip to main content

Vendor/product archive

webmin / usermin CVEs

Beta · best-effort

22 CVEs tagged to webmin / usermin1 Critical, 1 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2015-2079

Published Apr 28, 2025

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-44762

Published Oct 16, 2024

A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36453

Published Jul 10, 2024

Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41157

Published Sep 16, 2023

Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creat…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41160

Published Sep 14, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the key name fie…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41159

Published Sep 14, 2023

A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML by editing…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41156

Published Sep 14, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the save t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41162

Published Sep 13, 2023

A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the file mask fiel…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41158

Published Sep 13, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41155

Published Sep 13, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41154

Published Sep 13, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the value fiel…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41152

Published Sep 13, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the handle prog…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41161

Published Sep 7, 2023

Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the key comment to different pages su…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41153

Published Aug 29, 2023

A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via options for the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35132

Published Oct 25, 2022

Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4897

Published Apr 12, 2017

Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3884

Published Jul 20, 2014

Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3883

Published Jun 21, 2014

Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4568

Published Jan 5, 2010

Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0720

Published Feb 12, 2008

Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3156

Published Jun 11, 2007

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1