Vulnerabilities (CVE)

Filtered by vendor Microweber Subscribe
Filtered by product Microweber
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2368 1 Microweber 1 Microweber 2022-07-15 7.5 HIGH 9.8 CRITICAL
Business Logic Errors in GitHub repository microweber/microweber prior to 1.2.20.
CVE-2020-23138 1 Microweber 1 Microweber 2020-11-20 7.5 HIGH 9.8 CRITICAL
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.