Stored Cross-Site Scripting Vulnerability in Webmin by Virtualmin
CVE-2026-22678

5.1MEDIUM

Key Information:

Vendor

Webmin

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-22678?

Webmin, the popular web-based interface for system administration, has a stored cross-site scripting vulnerability in the email template description field within its System and Server Status module. This flaw enables low-privileged authenticated attackers to execute arbitrary commands by injecting unsanitized inputs. The malicious input is stored in the save_tmpl.cgi file and is later rendered unescaped in the list_tmpls.cgi, leading to potential exploitation in environments using vulnerable versions.

Affected Version(s)

Webmin 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamed Kohi (@0xHamy)
VulnCheck
.