CVE-2025-70792: Microweber
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Affected products
- Microweber Microweber: version 2.0.19 only
Published 2026-02-05. Last modified 2026-06-17.