Microweber prior to 1.2.12 contains a stored cross-site scripting vulnerability via the Type parameter in the body of POST request, which is triggered by Add/Edit Tax.
View the template here CVE-2022-0928.yaml
References:
https://github.com/ARPSyndicate/cvemon