CVE-2025-63261CVE-2025-63261HIGH7.8AWStats 8.0 is vulnerable to Command Injection via the open functionPublished: 2026-03-20Modified: 2026-04-07CVSS 3.xHIGH 7.8CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HReferenceshttps://github.com/eldy/AWStats/blob/develop/wwwroot/cgi-bin/awstats.plhttps://pentest-tools.com/PTT-2025-021-Code-Execution-in-AWStats.pdfhttps://lists.debian.org/debian-lts-announce/2026/03/msg00013.html