Microweber
by Microweber
Source repositories
CVEs (120)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4732 | Hig | 0.43 | 7.2 | 0.38 | Dec 27, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | ||
| CVE-2022-0281 | Hig | 0.43 | 7.5 | 0.12 | Jan 20, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2020-13405 | Hig | 0.43 | 7.5 | 0.14 | Jul 16, 2020 | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request. | ||
| CVE-2023-5318 | Hig | 0.42 | 7.5 | 0.01 | Sep 30, 2023 | Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2022-1036 | Hig | 0.42 | 7.5 | 0.01 | Mar 22, 2022 | Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2022-0913 | Hig | 0.42 | 7.5 | 0.01 | Mar 11, 2022 | Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0777 | Hig | 0.42 | 7.5 | 0.01 | Mar 1, 2022 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0660 | Hig | 0.42 | 7.5 | 0.07 | Feb 18, 2022 | Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2025-51502 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users. | ||
| CVE-2025-51501 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript. | ||
| CVE-2024-33298 | Med | 0.40 | 6.1 | 0.01 | Jan 10, 2025 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | ||
| CVE-2024-41381 | Med | 0.40 | 6.1 | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. | ||
| CVE-2024-41380 | Med | 0.40 | 6.1 | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. | ||
| CVE-2022-0698 | Med | 0.40 | 6.1 | 0.01 | Nov 25, 2022 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. | ||
| CVE-2021-33988 | Med | 0.40 | 6.1 | 0.01 | Oct 19, 2021 | Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form. | ||
| CVE-2018-19917 | Med | 0.40 | 6.1 | 0.02 | Mar 21, 2019 | Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. | ||
| CVE-2022-0921 | Med | 0.37 | 6.7 | 0.02 | Mar 11, 2022 | Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2020-23139 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2020 | Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise. | ||
| CVE-2020-23136 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2020 | Microweber v1.1.18 is affected by no session expiry after log-out. | ||
| CVE-2024-58289 | Med | 0.35 | 5.4 | 0.00 | Dec 11, 2025 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other… |
- risk 0.43cvss 7.2epss 0.38
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
- risk 0.43cvss 7.5epss 0.12
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
- risk 0.43cvss 7.5epss 0.14
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
- risk 0.42cvss 7.5epss 0.01
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.
- risk 0.42cvss 7.5epss 0.01
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.42cvss 7.5epss 0.01
Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
- risk 0.42cvss 7.5epss 0.01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
- risk 0.42cvss 7.5epss 0.07
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.
- risk 0.40cvss 6.1epss 0.01
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
- risk 0.40cvss 6.1epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
- risk 0.40cvss 6.1epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
- risk 0.40cvss 6.1epss 0.01
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
- risk 0.40cvss 6.1epss 0.02
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
- risk 0.37cvss 6.7epss 0.02
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.36cvss 5.5epss 0.00
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
- risk 0.36cvss 5.5epss 0.00
Microweber v1.1.18 is affected by no session expiry after log-out.
- risk 0.35cvss 5.4epss 0.00
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other…
Page 2 of 6