CVE-2025-51503: XSS
Published Jul 31, 2025
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.
Affected Software
3 affected components
Microweber CMS
composer/microweber/microweber>=2.0.0<=2.0.19
Microweber Microweber=2.0.0
Event History
Jul 31, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:32 PM
Data Sourced
via GitHub·06:32 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51503?
CVE-2025-51503 is rated as a high severity vulnerability due to its potential for arbitrary JavaScript execution.
2
How do I fix CVE-2025-51503?
To fix CVE-2025-51503, update Microweber CMS to the latest version beyond 2.0.19, where the vulnerability has been patched.
3
What impact does CVE-2025-51503 have on Microweber CMS?
CVE-2025-51503 allows attackers to inject malicious scripts into user profiles, compromising admin browser security.
4
Is CVE-2025-51503 exploitable without authentication?
Exploitation of CVE-2025-51503 typically requires user authentication, making it primarily a risk to authenticated users.
5
Which versions of Microweber CMS are affected by CVE-2025-51503?
Microweber CMS versions 2.0.0 to 2.0.19 are affected by CVE-2025-51503.