High severity8.3NVD Advisory· Published Oct 24, 2025· Updated Jun 17, 2026
CVE-2025-60954
CVE-2025-60954
Description
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:microweber:microweber:2.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microweber:microweber:2.0.0:*:*:*:*:*:*:*
- (no CPE)range: <2.0
- Microweber/CMSdescription
Patches
Vulnerability mechanics
References
2- gist.github.com/progprnv/feae2b76f2db0cb2ac6e14b1bf7d8646nvdExploitThird Party Advisory
- github.com/progprnv/CVE-Reports/blob/main/CVE-2025-60954nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.