CVE-2023-41158: Webmin Usermin

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program.

Affected products

  • Webmin Usermin: version 2.000 only

Published 2023-09-13. Last modified 2026-06-17.