Vulnerabilities (CVE)

Filtered by vendor Microweber Subscribe
Filtered by product Microweber
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6832 1 Microweber 1 Microweber 2023-12-21 N/A 4.3 MEDIUM
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-6599 1 Microweber 1 Microweber 2023-12-12 N/A 4.3 MEDIUM
Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-6566 1 Microweber 1 Microweber 2023-12-12 N/A 6.5 MEDIUM
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-47379 1 Microweber 1 Microweber 2023-11-15 N/A 5.4 MEDIUM
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
CVE-2023-5976 1 Microweber 1 Microweber 2023-11-14 N/A 4.3 MEDIUM
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
CVE-2022-0762 1 Microweber 1 Microweber 2023-08-02 4.0 MEDIUM 4.3 MEDIUM
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-2470 1 Microweber 1 Microweber 2022-07-26 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2495 1 Microweber 1 Microweber 2022-07-26 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2300 1 Microweber 1 Microweber 2022-07-12 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2280 1 Microweber 1 Microweber 2022-07-08 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2252 1 Microweber 1 Microweber 2022-07-07 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2174 1 Microweber 1 Microweber 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVE-2022-2130 1 Microweber 1 Microweber 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
CVE-2022-1584 1 Microweber 1 Microweber 2022-05-11 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim
CVE-2022-1555 1 Microweber 1 Microweber 2022-05-11 4.3 MEDIUM 6.1 MEDIUM
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...
CVE-2022-1504 1 Microweber 1 Microweber 2022-05-05 4.3 MEDIUM 6.1 MEDIUM
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
CVE-2022-1439 1 Microweber 1 Microweber 2022-04-29 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.
CVE-2022-0688 1 Microweber 1 Microweber 2022-02-28 4.0 MEDIUM 4.9 MEDIUM
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0678 1 Microweber 1 Microweber 2022-02-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0689 1 Microweber 1 Microweber 2022-02-26 5.0 MEDIUM 5.3 MEDIUM
Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0690 1 Microweber 1 Microweber 2022-02-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0638 1 Microweber 1 Microweber 2022-02-25 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0597 1 Microweber 1 Microweber 2022-02-23 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0596 1 Microweber 1 Microweber 2022-02-23 4.0 MEDIUM 4.3 MEDIUM
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0560 1 Microweber 1 Microweber 2022-02-17 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0558 1 Microweber 1 Microweber 2022-02-17 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0506 1 Microweber 1 Microweber 2022-02-11 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0505 1 Microweber 1 Microweber 2022-02-11 4.3 MEDIUM 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0504 1 Microweber 1 Microweber 2022-02-11 4.0 MEDIUM 6.5 MEDIUM
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0379 1 Microweber 1 Microweber 2022-02-02 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0378 1 Microweber 1 Microweber 2022-02-02 4.3 MEDIUM 5.4 MEDIUM
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0277 1 Microweber 1 Microweber 2022-01-26 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0278 1 Microweber 1 Microweber 2022-01-26 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2021-33988 1 Microweber 1 Microweber 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2020-23136 1 Microweber 1 Microweber 2020-11-20 2.1 LOW 5.5 MEDIUM
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-23139 1 Microweber 1 Microweber 2020-11-20 2.1 LOW 5.5 MEDIUM
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVE-2018-19917 1 Microweber 1 Microweber 2019-04-24 4.3 MEDIUM 6.1 MEDIUM
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
CVE-2018-1000826 1 Microweber 1 Microweber 2019-01-15 4.3 MEDIUM 6.1 MEDIUM
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.