Webmin vendor intelligence
Webmin Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Webmin products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 2
- Known exploited vulnerabilities affecting Webmin products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Webmin KEVs with sensor-observed exploitation activity
The catalog gap matters for Webmin exposure
One of the two exploited Webmin CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss half of this vendor portfolio.
- 50%
- Covered by CISA
- 50%
- Beyond CISA
- 1
- Product families
Attested Webmin CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2019-15642
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval... |
Webmin | High | Beyond CISA | 05 Jul 2025 |
|
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. |
Webmin | Confirmed | In CISA | 25 Mar 2022 |
No Webmin CVEs match this search or filter.
Showing 2 of 2 Webmin known exploited vulnerabilities.
Recurring weakness patterns
Neutralization and control account for two mapped occurrences across this Webmin KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.