Known Vulnerabilities for Webmin by Webmin
Listed below are 10 of the newest known vulnerabilities associated with "Webmin" by "Webmin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56022 json | Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowi... | Not Provided | 2026-06-18 | 2026-08-11 |
| CVE-2026-56021 json | Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a ... | Not Provided | 2026-06-18 | 2026-06-24 |
| CVE-2026-56020 json | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client ce... | Not Provided | 2026-06-18 | 2026-08-11 |
| CVE-2026-42210 json | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that requ... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-22678 json | Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the Syste... | Not Provided | 2026-05-21 | 2026-07-14 |
| CVE-2023-43309 json | There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field... | 4.8 - MEDIUM | 2023-09-21 | 2023-09-22 |
| CVE-2023-41163 json | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inje... | 6.1 - MEDIUM | 2023-08-30 | 2023-09-05 |
| CVE-2023-41155 json | A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows r... | 5.4 - MEDIUM | 2023-09-13 | 2023-09-18 |
| CVE-2023-40986 json | A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to ... | 5.4 - MEDIUM | 2023-09-15 | 2026-07-09 |
| CVE-2023-40985 json | An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting ... | 5.4 - MEDIUM | 2023-09-15 | 2026-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Webmin | Webmin | 1.962 | |||
| Application | Webmin | Webmin | 1.941 | |||
| Application | Webmin | Webmin | 1.930 | |||
| Application | Webmin | Webmin | 1.920 | |||
| Application | Webmin | Webmin | 1.910 | |||
| Application | Webmin | Webmin | 1.900 | |||
| Application | Webmin | Webmin | 1.890 | |||
| Application | Webmin | Webmin | 1.881 | |||
| Application | Webmin | Webmin | 1.880 | |||
| Application | Webmin | Webmin | 1.870 | |||
| Application | Webmin | Webmin | 1.860 | |||
| Application | Webmin | Webmin | 1.850 | |||
| Application | Webmin | Webmin | 1.840 | |||
| Application | Webmin | Webmin | 1.831 | |||
| Application | Webmin | Webmin | 1.830 | |||
| Application | Webmin | Webmin | 1.820 | |||
| Application | Webmin | Webmin | 1.810 | |||
| Application | Webmin | Webmin | 1.801 | |||
| Application | Webmin | Webmin | 1.791 | |||
| Application | Webmin | Webmin | 1.780 |