CVE Tools

Virtualmin

10 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Virtualmin, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Virtualmin CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Virtualmin CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High220%
  • Medium880%

Latest CVEs

The 10 most recently published vulnerabilities affecting Virtualmin.

  1. CVE-2024-45692Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.7.5
  2. CVE-2024-2169Implementations of UDP application protocols are susceptible to network loops and denial of service7.5
  3. CVE-2023-47096A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Cl...5.4
  4. CVE-2023-47095A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or ...5.4
  5. CVE-2023-47099A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description field while creating ...5.4
  6. CVE-2023-47098A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the re...4.8
  7. CVE-2023-47097A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Template name ...5.4
  8. CVE-2023-47094A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name fiel...5.4
  9. CVE-2018-18208Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.6.1
  10. CVE-2018-18207Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store