Microweber prior to 1.2.12 contains a stored cross-site scripting vulnerability via the Type parameter in the body of POST request, which is triggered by Add/Edit Tax.
id: CVE-2022-0928
info:
name: Microweber < 1.2.12 - Stored Cross-Site Scripting
author: amit-jd
...