Junglewise Threat Intelligence

CVE-2026-5696: Microweber reflected cross-site scripting in admin settings

CVE-2026-5696 · Severity: info · Published 2026-09-23

Technologies: Microweber. Vendors: Microweber.

Executive brief

Microweber is a website builder and online shop platform. The administration panel contains a reflected XSS vulnerability in the settings endpoint that allows attackers to inject malicious JavaScript code. An authenticated admin tricked into clicking a malicious link could have their session hijacked, sensitive information stolen, or malicious actions performed on their behalf.

Technical details

A reflected XSS vulnerability exists in the 'group' parameter of the '/admin/settings' endpoint in the Microweber administration panel. The vulnerability requires high-privilege user interaction (authenticated admin must visit a malicious link), but enables session hijacking, credential theft, or unauthorized actions within the administrative interface. No fix has been reported as of the advisory date.

Affected products

  • Microweber Microweber v2.0.19

Timeline

  • 2026-09-23: disclosed: Published in NVD
  • 2026-06-01: advisory: INCIBE-CERT advisory INCIBE-2026-661 published

References

Related threats