VYPR

Vendor CVEs

Microweber

All CVEs

120 total · sorted by risk
  • CVE-2020-23138CriNov 9, 2020
    risk 0.64cvss 9.8epss 0.01

    An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.

  • CVE-2023-49052HigNov 30, 2023
    risk 0.57cvss 8.8epss 0.02

    File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

  • CVE-2023-1877CriApr 5, 2023
    risk 0.57cvss 9.8epss 0.02

    Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

  • CVE-2022-33012HigNov 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

  • CVE-2021-36461HigJul 15, 2022
    risk 0.57cvss 8.8epss 0.01

    An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

  • CVE-2022-0895CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.02

    Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2025-60954HigOct 24, 2025
    risk 0.54cvss 8.3epss 0.00

    Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including…

  • CVE-2022-1631HigMay 9, 2022
    risk 0.54cvss 8.8epss 0.09

    Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows…

  • CVE-2020-23140HigNov 9, 2020
    risk 0.53cvss 8.1epss 0.01

    Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.

  • CVE-2020-13241HigMay 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.

  • CVE-2023-2240HigApr 22, 2023
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

  • CVE-2022-0896HigMar 9, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2025-51504HigAug 1, 2025
    risk 0.49cvss 7.6epss 0.00

    Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

  • CVE-2025-51503HigJul 31, 2025
    risk 0.49cvss 7.6epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

  • CVE-2023-48122HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

  • CVE-2026-12198HigJun 15, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to…

  • CVE-2022-0557HigFeb 11, 2022
    risk 0.47cvss 7.2epss 0.51

    OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-0666HigFeb 18, 2022
    risk 0.45cvss 7.5epss 0.44

    CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2020-28337HigFeb 15, 2021
    risk 0.44cvss 7.2epss 0.17

    A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload…

  • CVE-2025-34076HigJul 2, 2025
    risk 0.43cvss 7.2epss 0.01

    An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying…

  • CVE-2022-4732HigDec 27, 2022
    risk 0.43cvss 7.2epss 0.38

    Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

  • CVE-2022-0281HigJan 20, 2022
    risk 0.43cvss 7.5epss 0.12

    Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2020-13405HigJul 16, 2020
    risk 0.43cvss 7.5epss 0.14

    userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

  • CVE-2023-5318HigSep 30, 2023
    risk 0.42cvss 7.5epss 0.01

    Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2022-1036HigMar 22, 2022
    risk 0.42cvss 7.5epss 0.01

    Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

  • CVE-2022-0913HigMar 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0777HigMar 1, 2022
    risk 0.42cvss 7.5epss 0.01

    Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0660HigFeb 18, 2022
    risk 0.42cvss 7.5epss 0.07

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2025-51502MedAug 1, 2025
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.

  • CVE-2025-51501MedAug 1, 2025
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.

  • CVE-2024-33298MedJan 10, 2025
    risk 0.40cvss 6.1epss 0.01

    Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

  • CVE-2024-41381MedAug 5, 2024
    risk 0.40cvss 6.1epss 0.00

    microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

  • CVE-2024-41380MedAug 5, 2024
    risk 0.40cvss 6.1epss 0.00

    microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

  • CVE-2022-0698MedNov 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

  • CVE-2021-33988MedOct 19, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.

  • CVE-2018-19917MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.

  • CVE-2022-0921MedMar 11, 2022
    risk 0.37cvss 6.7epss 0.02

    Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

  • CVE-2020-23139MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.

  • CVE-2020-23136MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Microweber v1.1.18 is affected by no session expiry after log-out.

  • CVE-2024-58289MedDec 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other…

  • CVE-2023-6566MedDec 7, 2023
    risk 0.35cvss 6.5epss 0.00

    Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2023-2239MedApr 22, 2023
    risk 0.35cvss 6.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

  • CVE-2022-2368MedJul 11, 2022
    risk 0.35cvss 6.5epss 0.01

    Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

  • CVE-2022-0724MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0721MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0505MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-0504MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-0277MedJan 20, 2022
    risk 0.35cvss 6.5epss 0.01

    Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2025-70792MedFeb 5, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's…

  • CVE-2025-70791MedFeb 5, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the…

Page 1 of 3