CVE-2025-70791

MEDIUM

Microweber < 2.0.20 - XSS

Title source: rule
STIX 2.1

Description

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

Scores

CVSS v3 6.1
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
microweber/microweber 2.0.19
microweber/microweber 0 - 2.0.20Packagist
Published Feb 05, 2026
Tracked Since Feb 18, 2026