๐Ÿ” CVE Alert

CVE-2026-49243

UNKNOWN 0.0

Webmin: Reflected XSS in the Configuration module

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.

CWE CWE-79
Vendor webmin
Product webmin
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for webmin webmin

Be the first to know when new unknown vulnerabilities affecting webmin webmin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

webmin / webmin
< 2.650

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/webmin/webmin/security/advisories/GHSA-hv4w-p8jq-2rp5 github.com: https://github.com/webmin/webmin/commit/2d016751399ed0f4159e72a6cbcd63694a84dabf github.com: https://github.com/webmin/webmin/releases/tag/2.650