CVE Tools

Webmin

109 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Webmin, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Webmin CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Webmin CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-053
2026-063
2026-071
2026-080
2026-090

Severity

How the 109 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1211%
  • High2927%
  • Medium5955%
  • Low77%

Latest CVEs

The 15 most recently published vulnerabilities affecting Webmin.

  1. CVE-2026-42210Webmin 2FA requirement bypass—
  2. CVE-2026-56020Webmin HTTP header authentication bypass8.1
  3. CVE-2026-56021Webmin information disclosure via regex pattern5.3
  4. CVE-2026-56022Webmin MFA bypass5.3
  5. CVE-2026-49103Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.—
  6. CVE-2026-49102Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).6.1
  7. CVE-2026-22678Webmin < 2.641 Stored XSS via System and Server Status5.4
  8. CVE-2025-67738squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to...8.5
  9. CVE-2025-61541Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_em...7.1
  10. CVE-2025-2774Уязвимость веб-панели управления сервером Webmin, позволяющая нарушителю повысить свои привилегии8.8
  11. CVE-2024-12828Webmin CGI Command Injection Remote Code Execution Vulnerability8.8
  12. BDU:2024-07259Уязвимость панели управления хостингом Webmin, связанная с некорректными разрешениями и привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности5.4
  13. CVE-2024-45692Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.7.5
  14. CVE-2024-36453Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be ...6.1
  15. CVE-2024-36452Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a ...3.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store