Multiple vulnerabilities in the Microweber administration panel
Posted date 01/06/2026
Identificador
INCIBE-2026-661
Importance
4 - High
Affected Resources
Microweber administration panel, version v2.0.19.
Description
INCIBE has coordinated the publication of two vulnerabilities, one high-severity and one medium-severity, affecting Microweber, a website builder with an online shop. The vulnerabilities were discovered by David Aparicio Salcedo.
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:
- CVE-2026-5695: CVSS v4.0: 8.4 | CVSS AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-434
- CVE-2026-5696: CVSS v4.0: 5.9 | CVSS AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N | CWE-79
Solution
There is no reported solution at this time.
Detail
- CVE-2026-5695: Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.
- CVE-2026-5696: Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.
CVE
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-5695 | Alta | No | Microweber |
| CVE-2026-5696 | Media | No | Microweber |
References list
Etiquetas


