Junglewise Threat Intelligence

CVE-2025-2214: Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler

CVE-2025-2214 · Severity: low · CVSS 3.1 · Published 2025-03-12

Technologies: microweber/microweber (Packagist). Vendors: Packagist.

Executive brief

Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler

Affected products

  • Packagist microweber/microweber

Related threats