CVE-2025-63261

AWStats 8.0 is vulnerable to Command Injection via the open function
Configurations

Configuration 1 (hide)

cpe:2.3:a:awstats:awstats:7.9:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-20 21:17

Updated : 2026-06-17 09:53


NVD link : CVE-2025-63261

Mitre link : CVE-2025-63261

CVE.ORG link : CVE-2025-63261


JSON object : View

Products Affected

awstats

  • awstats

debian

  • debian_linux
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')