Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5jg5-xqfw-rv92 | Microweber has a Cross-site Scripting vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 05 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-05T20:53:48.883Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70791
Updated: 2026-02-05T20:51:38.197Z
Status : Awaiting Analysis
Published: 2026-02-05T17:16:13.000
Modified: 2026-02-05T21:15:52.277
Link: CVE-2025-70791
No data.
OpenCVE Enrichment
No data.
Github GHSA