CVE-2026-22678: Webmin

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi.

Affected products

  • Webmin Webmin: before 2.641 (fixed in 2.641)

Published 2026-05-21. Last modified 2026-07-23.