CVE-2026-5696
Multiple vulnerabilities in the Microweber administration panel
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.
| CWE | CWE-79 |
| Vendor | microweber |
| Product | administration panel |
| Published | Sep 23, 2026 |
| Last Updated | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for microweber administration panel
Be the first to know when new unknown vulnerabilities affecting microweber administration panel are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Microweber / Administration panel
2.0.19
References
Credits
David Aparicio Salcedo