CVE-2024-33299: Microweber

Medium severity, CVSS 4.7. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

Affected products

Published 2025-01-10. Last modified 2026-06-17.