CVE-2025-51502

Publication date

2025-08-01 00:00:00

Family

mitre

State

PUBLISHED

Description

Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.