CVE-2024-33297: Microweber

Medium severity, CVSS 4.7. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

Affected products

Published 2025-01-10. Last modified 2026-06-17.