Products: 1
    Vulnerabilities: 27
    Known Exploited: 0
    3
    Critical Level Threats
    7
    High Level Threats
    15
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-63261

    AWStats 8.0 is vulnerable to Command Injection via the open function

    Last Modified: Apr 08, 2026
    Published: Mar 20, 2026

    CVE-2025-49890

    WordPress Organic Beauty Theme <= 1.4.6 - PHP Object Injection Vulnerability

    Last Modified: Apr 23, 2026
    Published: Aug 20, 2025

    CVE-2022-46391

    AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

    Last Modified: Apr 24, 2025
    Published: Dec 04, 2022

    CVE-2020-35176

    In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

    Last Modified: Nov 21, 2024
    Published: Dec 11, 2020

    CVE-2020-29600

    In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

    Last Modified: Nov 21, 2024
    Published: Dec 07, 2020
    Items Per Page
    Awstats Vulnerabilities & Security CVEs | CVE-DB