CVE Tools

Virtualmin

6 CVEs tracked since 2023. Since Oct 2023, none of them reached CISA KEV.

Virtualmin CVEs per month

Oct 2023 to Oct 2023. Point at a month, or focus the strip and use the arrow keys.
Virtualmin CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1060

Products

The products that kept showing up in Virtualmin's monthly top three, with their CVEs summed over those months.

  1. Virtualmin61 month

Latest CVEs

The 9 most recently published vulnerabilities affecting Virtualmin.

  1. CVE-2024-45692Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.7.5
  2. CVE-2023-47096A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Cl...5.4
  3. CVE-2023-47095A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or ...5.4
  4. CVE-2023-47099A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description field while creating ...5.4
  5. CVE-2023-47098A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the re...4.8
  6. CVE-2023-47097A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Template name ...5.4
  7. CVE-2023-47094A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name fiel...5.4
  8. CVE-2018-18208Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.6.1
  9. CVE-2018-18207Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.6.1

The record

Peak rank
#134 in Oct 2023
Busiest month shown
Oct 2023, 6 CVEs
Months with a KEV entry
0 since Oct 2023
Monthly snapshots
1 since 2023
Virtualmin's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store