CVE-2025-51502: XSS
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51502?
CVE-2025-51502 has a high severity rating due to its potential for arbitrary JavaScript execution by authenticated admin users.
How do I fix CVE-2025-51502?
To fix CVE-2025-51502, update Microweber CMS to the latest version where the reflected XSS vulnerability has been addressed.
What is the impact of CVE-2025-51502?
The impact of CVE-2025-51502 includes the ability for attackers to execute malicious scripts in the context of authenticated admin users, compromising site integrity.
Who is affected by CVE-2025-51502?
CVE-2025-51502 affects all versions of Microweber CMS 2.0 that include the vulnerable /admin/page/create endpoint with the layout parameter.
How is CVE-2025-51502 exploited?
CVE-2025-51502 can be exploited by crafting a malicious URL that includes a script in the layout parameter, executed when accessed by an admin user.