A vulnerability was found in Microweber CMS up to 2.0.20 and classified as problematic. Affected by this vulnerability is the function strip_unsafe of the file /api/save_content_admin of the component Content Tagging System. The manipulation of the argument tag_names results in cross site scripting.

This vulnerability is cataloged as CVE-2026-67617. The attack may be launched remotely. There is no exploit available.