Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.
https://github.com/progprnv/CVE-Reports/blob/main/CVE-2025-60954
https://github.com/microweber/microweber
https://gist.github.com/progprnv/feae2b76f2db0cb2ac6e14b1bf7d8646