PT-2026-6596 · Unknown · Microweber

Published

2026-02-05

·

Updated

2026-02-06

·

CVE-2025-70791

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microweber versions prior to 2.0.20
Description A Cross Site Scripting issue exists in the /admin/order/abandoned API endpoint of the software. An attacker can manipulate the orderDirection parameter within a crafted URL. By enticing a user with administrative privileges to visit this URL, the attacker can execute JavaScript code in the user's browser. The vulnerable parameter is orderDirection.
Recommendations Update to version 2.0.20 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-70791
GHSA-5JG5-XQFW-RV92

Affected Products

Microweber