Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microweber:microweber:2.0.19:*:*:*:*:*:*:* |
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microweber
Microweber microweber |
|
| Vendors & Products |
Microweber
Microweber microweber |
Thu, 05 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 05 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-02-05T00:00:00.000Z
Updated: 2026-02-05T20:50:03.356Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70792
Updated: 2026-02-05T20:47:52.294Z
Status : Analyzed
Published: 2026-02-05T17:16:13.103
Modified: 2026-02-10T18:54:33.153
Link: CVE-2025-70792
No data.