Vendor CVEs
Microweber
All CVEs
120 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-23138 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2020 | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension. | ||
| CVE-2023-49052 | Hig | 0.57 | 8.8 | 0.02 | Nov 30, 2023 | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component. | ||
| CVE-2023-1877 | Cri | 0.57 | 9.8 | 0.02 | Apr 5, 2023 | Command Injection in GitHub repository microweber/microweber prior to 1.3.3. | ||
| CVE-2022-33012 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2022 | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. | ||
| CVE-2021-36461 | Hig | 0.57 | 8.8 | 0.01 | Jul 15, 2022 | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini. | ||
| CVE-2022-0895 | Cri | 0.57 | 9.8 | 0.02 | Mar 10, 2022 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2025-60954 | Hig | 0.54 | 8.3 | 0.00 | Oct 24, 2025 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including… | ||
| CVE-2022-1631 | Hig | 0.54 | 8.8 | 0.09 | May 9, 2022 | Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows… | ||
| CVE-2020-23140 | Hig | 0.53 | 8.1 | 0.01 | Nov 9, 2020 | Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active. | ||
| CVE-2020-13241 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2020 | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file. | ||
| CVE-2023-2240 | Hig | 0.50 | 8.8 | 0.01 | Apr 22, 2023 | Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. | ||
| CVE-2022-0896 | Hig | 0.50 | 8.8 | 0.01 | Mar 9, 2022 | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2025-51504 | Hig | 0.49 | 7.6 | 0.00 | Aug 1, 2025 | Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field. | ||
| CVE-2025-51503 | Hig | 0.49 | 7.6 | 0.00 | Jul 31, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers. | ||
| CVE-2023-48122 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2023 | An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. | ||
| CVE-2026-12198 | Hig | 0.47 | 7.3 | 0.01 | Jun 15, 2026 | A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to… | ||
| CVE-2022-0557 | Hig | 0.47 | 7.2 | 0.51 | Feb 11, 2022 | OS Command Injection in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0666 | Hig | 0.45 | 7.5 | 0.44 | Feb 18, 2022 | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2020-28337 | Hig | 0.44 | 7.2 | 0.17 | Feb 15, 2021 | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload… | ||
| CVE-2025-34076 | Hig | 0.43 | 7.2 | 0.01 | Jul 2, 2025 | An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying… | ||
| CVE-2022-4732 | Hig | 0.43 | 7.2 | 0.38 | Dec 27, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | ||
| CVE-2022-0281 | Hig | 0.43 | 7.5 | 0.12 | Jan 20, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2020-13405 | Hig | 0.43 | 7.5 | 0.14 | Jul 16, 2020 | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request. | ||
| CVE-2023-5318 | Hig | 0.42 | 7.5 | 0.01 | Sep 30, 2023 | Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2022-1036 | Hig | 0.42 | 7.5 | 0.01 | Mar 22, 2022 | Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2022-0913 | Hig | 0.42 | 7.5 | 0.01 | Mar 11, 2022 | Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0777 | Hig | 0.42 | 7.5 | 0.01 | Mar 1, 2022 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0660 | Hig | 0.42 | 7.5 | 0.07 | Feb 18, 2022 | Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2025-51502 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users. | ||
| CVE-2025-51501 | Med | 0.40 | 6.1 | 0.01 | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript. | ||
| CVE-2024-33298 | Med | 0.40 | 6.1 | 0.01 | Jan 10, 2025 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | ||
| CVE-2024-41381 | Med | 0.40 | 6.1 | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. | ||
| CVE-2024-41380 | Med | 0.40 | 6.1 | 0.00 | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. | ||
| CVE-2022-0698 | Med | 0.40 | 6.1 | 0.01 | Nov 25, 2022 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. | ||
| CVE-2021-33988 | Med | 0.40 | 6.1 | 0.01 | Oct 19, 2021 | Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form. | ||
| CVE-2018-19917 | Med | 0.40 | 6.1 | 0.02 | Mar 21, 2019 | Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. | ||
| CVE-2022-0921 | Med | 0.37 | 6.7 | 0.02 | Mar 11, 2022 | Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2020-23139 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2020 | Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise. | ||
| CVE-2020-23136 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2020 | Microweber v1.1.18 is affected by no session expiry after log-out. | ||
| CVE-2024-58289 | Med | 0.35 | 5.4 | 0.00 | Dec 11, 2025 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other… | ||
| CVE-2023-6566 | Med | 0.35 | 6.5 | 0.00 | Dec 7, 2023 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2023-2239 | Med | 0.35 | 6.5 | 0.01 | Apr 22, 2023 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4. | ||
| CVE-2022-2368 | Med | 0.35 | 6.5 | 0.01 | Jul 11, 2022 | Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. | ||
| CVE-2022-0724 | Med | 0.35 | 6.5 | 0.01 | Feb 23, 2022 | Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0721 | Med | 0.35 | 6.5 | 0.01 | Feb 23, 2022 | Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0505 | Med | 0.35 | 6.5 | 0.01 | Feb 8, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0504 | Med | 0.35 | 6.5 | 0.01 | Feb 8, 2022 | Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2022-0277 | Med | 0.35 | 6.5 | 0.01 | Jan 20, 2022 | Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2025-70792 | Med | 0.33 | 6.1 | 0.00 | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's… | ||
| CVE-2025-70791 | Med | 0.33 | 6.1 | 0.00 | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the… |
- risk 0.64cvss 9.8epss 0.01
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
- risk 0.57cvss 8.8epss 0.02
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.
- risk 0.57cvss 9.8epss 0.02
Command Injection in GitHub repository microweber/microweber prior to 1.3.3.
- risk 0.57cvss 8.8epss 0.01
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
- risk 0.57cvss 8.8epss 0.01
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
- risk 0.57cvss 9.8epss 0.02
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
- risk 0.54cvss 8.3epss 0.00
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including…
- risk 0.54cvss 8.8epss 0.09
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows…
- risk 0.53cvss 8.1epss 0.01
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
- risk 0.51cvss 7.8epss 0.00
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
- risk 0.50cvss 8.8epss 0.01
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
- risk 0.49cvss 7.6epss 0.00
Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.
- risk 0.49cvss 7.6epss 0.00
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.
- risk 0.49cvss 7.5epss 0.01
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
- risk 0.47cvss 7.3epss 0.01
A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to…
- risk 0.47cvss 7.2epss 0.51
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
- risk 0.45cvss 7.5epss 0.44
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
- risk 0.44cvss 7.2epss 0.17
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload…
- risk 0.43cvss 7.2epss 0.01
An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying…
- risk 0.43cvss 7.2epss 0.38
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
- risk 0.43cvss 7.5epss 0.12
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
- risk 0.43cvss 7.5epss 0.14
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
- risk 0.42cvss 7.5epss 0.01
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.
- risk 0.42cvss 7.5epss 0.01
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.42cvss 7.5epss 0.01
Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
- risk 0.42cvss 7.5epss 0.01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
- risk 0.42cvss 7.5epss 0.07
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.
- risk 0.40cvss 6.1epss 0.01
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
- risk 0.40cvss 6.1epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
- risk 0.40cvss 6.1epss 0.00
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
- risk 0.40cvss 6.1epss 0.01
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
- risk 0.40cvss 6.1epss 0.02
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
- risk 0.37cvss 6.7epss 0.02
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.36cvss 5.5epss 0.00
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
- risk 0.36cvss 5.5epss 0.00
Microweber v1.1.18 is affected by no session expiry after log-out.
- risk 0.35cvss 5.4epss 0.00
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other…
- risk 0.35cvss 6.5epss 0.00
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
- risk 0.35cvss 6.5epss 0.01
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.
- risk 0.35cvss 6.5epss 0.01
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
- risk 0.35cvss 6.5epss 0.01
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
- risk 0.35cvss 6.5epss 0.01
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
- risk 0.35cvss 6.5epss 0.01
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
- risk 0.35cvss 6.5epss 0.01
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
- risk 0.35cvss 6.5epss 0.01
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's…
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the…
Page 1 of 3