CVE Database
/

CVE-2025-40697

Back to search

CVE-2025-40697

Published: Feb 19, 2026

Modified: Feb 24, 2026

PUBLISHED

Description

Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

VendorProductVersions

Lewe

WebMeasure

affected
all versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now