CVE-2025-60954

HIGH

Microweber CMS 2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

Scores

CVSS v3 8.3
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-521
Status published
Products (1)
microweber/microweber 2.0.0
Published Oct 24, 2025
Tracked Since Feb 18, 2026