CVE-2025-60954: High severity Microweber CMS vulnerability
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60954?
The severity of CVE-2025-60954 is high due to its potential for account compromise through weak password policies.
How do I fix CVE-2025-60954?
To fix CVE-2025-60954, implement stronger password policies that enforce minimum length and complexity requirements.
Who is affected by CVE-2025-60954?
CVE-2025-60954 affects all users of Microweber CMS version 2.0 who have the ability to reset passwords.
What are the risks of CVE-2025-60954?
The risks of CVE-2025-60954 include unauthorized access to user accounts, including administrative accounts, due to weak passwords.
Is CVE-2025-60954 a potential vector for attacks?
Yes, CVE-2025-60954 is a potential vector for attacks, as it allows users to set easily guessable passwords.