CVE-2023-43309: Webmin

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.

Affected products

  • Webmin Webmin: up to and including 2.002

Published 2023-09-21. Last modified 2026-06-17.