Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23376 | Microweber has Reflected XSS Vulnerability in the layout Parameter |
Github GHSA |
GHSA-mvj3-hc7j-vp74 | Microweber has Reflected XSS Vulnerability in the layout Parameter |
Tue, 19 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microweber microweber
|
|
| CPEs | cpe:2.3:a:microweber:microweber:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Microweber microweber
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microweber
Microweber cms |
|
| Vendors & Products |
Microweber
Microweber cms |
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-01T18:01:25.783Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51502
Updated: 2025-08-01T18:01:13.390Z
Status : Analyzed
Published: 2025-08-01T17:15:52.500
Modified: 2025-08-19T15:33:25.670
Link: CVE-2025-51502
No data.
OpenCVE Enrichment
Updated: 2025-08-12T12:05:48Z
EUVD
Github GHSA