VYPR

Microweber

by Microweber

Source repositories

CVEs (120)

  • CVE-2023-6566MedDec 7, 2023
    risk 0.35cvss 6.5epss 0.00

    Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2023-2239MedApr 22, 2023
    risk 0.35cvss 6.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

  • CVE-2022-2368MedJul 11, 2022
    risk 0.35cvss 6.5epss 0.01

    Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

  • CVE-2022-0724MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0721MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0505MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-0504MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-0277MedJan 20, 2022
    risk 0.35cvss 6.5epss 0.01

    Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2025-70792MedFeb 5, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's…

  • CVE-2025-70791MedFeb 5, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the…

  • CVE-2024-40101MedAug 6, 2024
    risk 0.33cvss 6.1epss 0.01

    A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

  • CVE-2023-5244MedSep 28, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2021-32856MedFeb 21, 2023
    risk 0.33cvss 6.1epss 0.01

    Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A…

  • CVE-2022-4647MedDec 22, 2022
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

  • CVE-2022-4617MedDec 21, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

  • CVE-2022-3245MedSep 20, 2022
    risk 0.33cvss 6.1epss 0.01

    HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.

  • CVE-2022-3242MedSep 20, 2022
    risk 0.33cvss 6.1epss 0.01

    Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

  • CVE-2022-2470MedJul 22, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

  • CVE-2022-2353MedJul 9, 2022
    risk 0.33cvss 6.1epss 0.01

    Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

  • CVE-2022-2252MedJun 29, 2022
    risk 0.33cvss 6.1epss 0.01

    Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

Page 3 of 6