CVE-2025-51503

EPSS 0.52%

Microweber Has Stored XSS Vulnerability in User Profile Fields

Published: 7/31/2025Modified: 8/1/2025
Also known as:GHSA-782f-gxj5-xvqc

Description

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P

References (5)