Stored Cross-Site Scripting Vulnerability in Webmin by Virtualmin
CVE-2026-22678
5.1MEDIUM
What is CVE-2026-22678?
Webmin, the popular web-based interface for system administration, has a stored cross-site scripting vulnerability in the email template description field within its System and Server Status module. This flaw enables low-privileged authenticated attackers to execute arbitrary commands by injecting unsanitized inputs. The malicious input is stored in the save_tmpl.cgi file and is later rendered unescaped in the list_tmpls.cgi, leading to potential exploitation in environments using vulnerable versions.
Affected Version(s)
Webmin 0
