CVE-2025-40697
Awaiting Analysis
Awaiting Analysis - Queue
Reflected XSS in Lewe WebMeasure /index.php Enables Data Theft
Publication date: 2026-02-19
Last updated on: 2026-02-19
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lewe | webmeasure | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |