
CVE-2025-70792 Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL a… https://www.cve.org/CVERecord?id=CVE-2025-70792
Post summary
The post announces a Cross Site Scripting vulnerability in Microweber 2.0.19’s /admin/category/create endpoint, noting that an attacker can manipulate the rel_id parameter via a crafted URL; no PoC, exploit, patch, or active exploitation is reported.
