CVE-2026-5696 PUBLISHED

Multiple vulnerabilities in the Microweber administration panel

Assigner: INCIBE
Reserved: 06.04.2026 Published: 23.09.2026 Updated: 23.09.2026

Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 5.9

Product Status

Vendor Microweber
Product Administration panel
Versions Default: unaffected
  • Version 2.0.19 is affected

Solutions

There is no reported solution at this time.

Credits

  • David Aparicio Salcedo finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE