Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650. | |
| Title | Webmin: Reflected XSS in the Configuration module | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T15:21:31.089Z
Reserved: 2026-05-28T14:33:01.178Z
Link: CVE-2026-49243
No data.
Status : Deferred
Published: 2026-09-29T15:17:26.173
Modified: 2026-09-29T15:17:26.310
Link: CVE-2026-49243
No data.
OpenCVE Enrichment
No data.