CVE-2024-33297: Microweber
Medium severity, CVSS 4.7. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function
Affected products
- Microweber Microweber: up to and including 2.0.9
Published 2025-01-10. Last modified 2026-06-17.