CVE-2026-65693: Microweber
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.
Affected products
- Microweber Microweber: up to and including 2.0.20
Published 2026-07-24. Last modified 2026-07-28.