---
id: CVE-2026-5696
title: Reflected Cross-Site Scripting (XSS) in Microweber
summary: >-
  Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in
  the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration
  panel. A successful exploit allows an attacker to trick an authenticated user
  int…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'
cwe:
  - CWE-79
vendor: Microweber
product: Administration panel
affected:
  - administration_panel 2.0.19
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:45:22.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5696'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-microweber-administration-panel
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T13:09:23.700269Z'
cvssSource: cna
ingestedAt: '2026-09-23T11:22:32.913Z'
---

## Overview

Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
