Microweber
by Microweber
Source repositories
CVEs (120)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0930 | Med | 0.24 | 4.8 | 0.01 | Mar 12, 2022 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2022-0926 | Med | 0.24 | 4.8 | 0.01 | Mar 12, 2022 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2022-0912 | Med | 0.24 | 4.8 | 0.01 | Mar 11, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0906 | Med | 0.24 | 4.8 | 0.01 | Mar 10, 2022 | Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12. | ||
| CVE-2022-0763 | Med | 0.24 | 4.8 | 0.01 | Feb 26, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2025-2214 | Low | 0.23 | 3.5 | 0.01 | Mar 12, 2025 | A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to… | ||
| CVE-2023-6832 | Med | 0.21 | 4.3 | 0.01 | Dec 15, 2023 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2023-6599 | Med | 0.21 | 4.3 | 0.00 | Dec 8, 2023 | Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2023-5976 | Med | 0.21 | 4.3 | 0.00 | Nov 7, 2023 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2022-0638 | Med | 0.21 | 4.3 | 0.00 | Feb 17, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0596 | Med | 0.21 | 4.3 | 0.01 | Feb 15, 2022 | Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0282 | Med | 0.21 | 4.3 | 0.01 | Jan 20, 2022 | Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2026-67617 | Med | 0.00 | 4.8 | 0.00 | Aug 3, 2026 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET… | ||
| CVE-2026-65693 | Hig | 0.00 | 7.2 | 0.00 | Jul 24, 2026 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in… | ||
| CVE-2026-65694 | Hig | 0.00 | 7.5 | 0.02 | Jul 23, 2026 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single… | ||
| CVE-2021-32857 | Med | 0.00 | 6.1 | 0.01 | Feb 21, 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | ||
| CVE-2022-0855 | Med | 0.00 | 6.1 | 0.01 | Mar 4, 2022 | Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4. | ||
| CVE-2018-17104 | Hig | 0.00 | 8.8 | 0.01 | Sep 16, 2018 | An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user. | ||
| CVE-2014-9464 | 0.00 | — | 0.02 | Jan 3, 2015 | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable. | |||
| CVE-2013-5984 | 0.00 | — | 0.03 | May 12, 2014 | Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter. |
- risk 0.24cvss 4.8epss 0.01
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.24cvss 4.8epss 0.01
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.24cvss 4.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
- risk 0.24cvss 4.8epss 0.01
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
- risk 0.24cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.
- risk 0.23cvss 3.5epss 0.01
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to…
- risk 0.21cvss 4.3epss 0.01
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
- risk 0.21cvss 4.3epss 0.00
Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.
- risk 0.21cvss 4.3epss 0.00
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
- risk 0.21cvss 4.3epss 0.01
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
- risk 0.21cvss 4.3epss 0.01
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
- risk 0.00cvss 4.8epss 0.00
Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET…
- risk 0.00cvss 7.2epss 0.00
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in…
- risk 0.00cvss 7.5epss 0.02
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single…
- risk 0.00cvss 6.1epss 0.01
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
- risk 0.00cvss 6.1epss 0.01
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
- risk 0.00cvss 8.8epss 0.01
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
- CVE-2014-9464Jan 3, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.
- CVE-2013-5984May 12, 2014risk 0.00cvss —epss 0.03
Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter.
Page 6 of 6