Virtualmin is a web-based control panel for managing virtual hosting environments, with its vulnerability exposure concentrated in a single, niche product serving system administrators and small-to-medium hosting providers. The durable signal is application-layer input handling, where the recurring weakness classes—cross-site scripting, injection flaws, and infinite loops—reflect the challenges of safely processing untrusted input in a management interface that bridges user configuration and server commands. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtualmin over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45692HIGH Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. | Sep 4, 2024 | 7.5 | 21 | NO | NO |
CVE-2018-18207MEDIUM Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. | Oct 10, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-18208MEDIUM Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI. | Oct 10, 2018 | 6.1 | 20 | NO | NO |
CVE-2023-47095MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitra | Nov 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-47094MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via t | Nov 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-47099MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description fiel | Nov 1, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-47097MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via t | Nov 1, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-47096MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script o | Nov 1, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-47098MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script o | Nov 1, 2023 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtualmin.
Media articles that mention a CVE ID that affects a product developed by Virtualmin — matched by CVE ID, not by vendor name.