CVE-2025-51501
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.
MEDIUM · CVSS 6.1
EPSS 0.00258
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0