Home

Description

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

PUBLISHED Reserved 2026-01-09 | Published 2026-02-05 | Updated 2026-02-05 | Assigner mitre

References

github.com/...ommit/aa0791fc286d785ccd33ccc706f7bb3ed05b1d7f

gist.github.com/...ktenwald/f4b0d1edbb87e75c17c639ca0bacba57

cve.org (CVE-2025-70792)

nvd.nist.gov (CVE-2025-70792)

Download JSON