Webmin
This hub aggregates every CVE we track for Webmin, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
107
CVEs tracked
12
Critical
29
High
1
In CISA KEV
Severity distribution
MEDIUM59HIGH29CRITICAL12LOW7
Monthly trend
2
0
0
1
0
0
0
0
1
0
0
0
0
1
0
1
0
0
0
0
2
3
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Webmin.
- CVE-2026-56020Webmin HTTP header authentication bypass8.1
- CVE-2026-56021Webmin information disclosure via regex pattern5.3
- CVE-2026-56022Webmin MFA bypass5.3
- CVE-2026-49102Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).6.1
- CVE-2026-22678Webmin < 2.641 Stored XSS via System and Server Status5.4
- CVE-2025-67738squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to...8.5
- CVE-2025-61541Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_em...7.1
- CVE-2025-2774Уязвимость веб-панели управления сервером Webmin, позволяющая нарушителю повысить свои привилегии8.8
- CVE-2024-12828Webmin CGI Command Injection Remote Code Execution Vulnerability8.8
- BDU:2024-07259Уязвимость панели управления хостингом Webmin, связанная с некорректными разрешениями и привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности5.4
- CVE-2024-45692Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.7.5
- CVE-2024-36453Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be ...6.1
- CVE-2024-36452Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a ...3.1
- CVE-2024-36451Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked b...8.8
- CVE-2024-36450Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user wh...5.4
Product normalization is registry-driven with AI assist and human review. How it works