GHSA-mvj3-hc7j-vp74
GitHub Security Advisory
Microweber has Reflected XSS Vulnerability in the layout Parameter
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.
Affected Packages
Packagist
microweber/microweber
Affected versions:
2.0.0
(last affected: 2.0.19)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 10, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.