Unknown · Microweber Cms2.0 · CVE-2025-51501
**Name of the Vulnerable Software and Affected Versions**
Microweber CMS2.0
**Description**
Reflected Cross-Site Scripting (XSS) exists in the `id` parameter of the `/live edit.module settings` API endpoint, allowing for the execution of arbitrary JavaScript.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.