← Vulnerability feed

Vulnerability record · CVE-2025-2214 · published 12 March 2025

CVE-2025-2214: Microweber cross-site scripting vulnerability

Microweber · Microweber

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.1 CVSS 4.0 Medium EPSS 0.51% · top 58.9% CWE-79 · Cross-site scriptingCWE-94 · Code injection
5.1CVSS 4.0 base score, v2 4.0
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Fewword/Poc/blob/main/microweber/mwb-poc1.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.299285 Permissions RequiredVDB Entry
https://vuldb.com/?id.299285 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.512032 Third Party AdvisoryVDB Entry
https://github.com/Fewword/Poc/blob/main/microweber/mwb-poc1.md ExploitThird Party Advisory

Track CVE-2025-2214 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1877Microweber command injection vulnerabilityCommand Injection in GitHub repository microweber/microweber prior to 1.3.3.EPSS 1.8%9.8CVE-2022-2368Microweber authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.EPSS 1.1%9.8CVE-2022-0895Microweber vulnerabilityStatic Code Injection in GitHub repository microweber/microweber prior to 1.3.EPSS 1.7%9.8CVE-2020-23138Microweber unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…EPSS 1.3%8.8CVE-2023-49052Microweber unrestricted file upload vulnerabilityFile Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…EPSS 2.4%8.8CVE-2023-2240Microweber improper privilege management vulnerabilityImproper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.EPSS 0.71%8.8CVE-2022-33012Microweber injection vulnerabilityMicroweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.EPSS 1.4%8.8CVE-2021-36461Microweber unrestricted file upload vulnerabilityAn Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2025-2214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.