Reflected Cross-Site Scripting Vulnerability in Microweber Administration Panel
CVE-2026-5696
5.9MEDIUM
What is CVE-2026-5696?
A reflected cross-site scripting (XSS) vulnerability exists in the Microweber administration panel, specifically within the āgroupā parameter of the ā/admin/settingsā endpoint. This security flaw can be exploited by a malicious actor to inject harmful JavaScript code, prompting authenticated users to unknowingly execute this code in their browsers. Such an attack may allow unauthorized actions, the theft of sensitive information, or even session hijacking, compromising user security and system integrity.
Affected Version(s)
Administration panel 2.0.19
