Multiple vulnerabilities in the Microweber administration panel

Posted date 01/06/2026
Identificador
INCIBE-2026-661
Importance
4 - High
Affected Resources

Microweber administration panel, version v2.0.19.

Description

INCIBE has coordinated the publication of two vulnerabilities, one high-severity and one medium-severity, affecting Microweber, a website builder with an online shop. The vulnerabilities were discovered by David Aparicio Salcedo.

These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:

  • CVE-2026-5695: CVSS v4.0: 8.4 | CVSS AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-434
  • CVE-2026-5696: CVSS v4.0: 5.9 | CVSS AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N | CWE-79
Solution

There is no reported solution at this time.

Detail
  • CVE-2026-5695: Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.
  • CVE-2026-5696: Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-5695 Alta No Microweber
CVE-2026-5696 Media No Microweber
References list