CVE-2025-51503

HIGH

Microweber 2.0 - Stored Cross-Site Scripting in User Profile Fields

Title source: llm
STIX 2.1

Description

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

Scores

CVSS v3 7.6
EPSS 0.0045
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
microweber/microweber 2.0.0
microweber/microweber 2.0.0Packagist
Published Jul 31, 2025
Tracked Since Feb 18, 2026