Microweber Administration panel

2 known vulnerabilities in Microweber Administration panel, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-5696 CVSS 5.9 medium Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in…
  • CVE-2026-5695 CVSS 8.4 high Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to…