CVE-2025-70792
EUVD-2025-20682305.02.2026, 17:16
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microweber | microweber | 2.0.19 |
𝑥
= Vulnerable software versions