
CVE-2025-70791 Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a craft… https://www.cve.org/CVERecord?id=CVE-2025-70791
Post summary
A Cross Site Scripting vulnerability (CVE‑2025‑70791) was disclosed affecting the "/admin/order/abandoned" endpoint of Microweber 2.0.19, triggered by manipulating the "orderDirection" parameter.
