Skip to content
Noroxi

microweber records

115 published records for vendor microweber.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.9%
Pre-auth RCE
9
With a fix record
65.2%
Median publish → KEV
No record has entered KEV

All records

115 records
  • OS Command Injection in microweber/microweber

    HighCVSS 7.2Proof of conceptEPSS 51%

    microweber · microweberFeb 11, 2022

  • CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber

    HighCVSS 7.5Proof of conceptEPSS 44%

    microweber · microweberFeb 18, 2022

  • Command Injection in microweber/microweber

    CriticalCVSS 9.8No exploitEPSS 2%

    microweber · microweberApr 5, 2023

  • Static Code Injection in microweber/microweber

    CriticalCVSS 9.8No exploitEPSS 2%

    microweber · microweberMar 10, 2022

  • CVE-2022-4732
    39Monitor

    Unrestricted Upload of File with Dangerous Type in microweber/microweber

    HighCVSS 7.2No exploitEPSS 38%

    microweber · microweberDec 27, 2022

  • An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.

    CriticalCVSS 9.8No exploitEPSS 1%

    microweber · microweberNov 9, 2020

  • CVE-2022-2368
    39Monitor

    Authentication Bypass by Spoofing in microweber/microweber

    CriticalCVSS 9.8No exploitEPSS 1%

    microweber · microweberJul 11, 2022

  • CVE-2022-1631
    38Monitor

    Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber

    HighCVSS 8.8Proof of conceptEPSS 9%

    microweber · microweberMay 9, 2022

  • File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload f

    HighCVSS 8.8Proof of conceptEPSS 2%

    microweber · microweberNov 30, 2023

  • Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

    HighCVSS 8.8No exploitEPSS 1%

    microweber · microweberNov 22, 2022

  • CVE-2022-0896
    35Monitor

    Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber

    HighCVSS 8.8No exploitEPSS 1%

    microweber · microweberMar 9, 2022

  • An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section

    HighCVSS 8.8No exploitEPSS 1%

    microweber · microweberJul 15, 2022

  • An issue was discovered in Microweber 1.0.7.

    HighCVSS 8.8No exploitEPSS 1%

    microweber · microweberSep 16, 2018

  • CVE-2023-2240
    35Monitor

    Improper Privilege Management in microweber/microweber

    HighCVSS 8.8No exploitEPSS 1%

    microweber · microweberApr 21, 2023

  • userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database

    HighCVSS 7.5Proof of conceptEPSS 14%

    microweber · microweberJul 16, 2020

  • A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code exec

    HighCVSS 7.2Proof of conceptEPSS 17%

    microweber · microweberFeb 15, 2021

  • CVE-2022-0281
    33Monitor

    Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber

    HighCVSS 7.5Proof of conceptEPSS 10%

    microweber · microweberJan 20, 2022

  • Microweber CMS 2.0 has Weak Password Requirements.

    HighCVSS 8.3No exploitEPSS 0%

    microweber · microweberOct 24, 2025

  • CVE-2022-0660
    32Monitor

    Generation of Error Message Containing Sensitive Information in microweber/microweber

    HighCVSS 7.5Proof of conceptEPSS 7%

    microweber · microweberFeb 18, 2022

  • Microweber 1.1.18 is affected by insufficient session expiration.

    HighCVSS 8.1No exploitEPSS 1%

    microweber · microweberNov 9, 2020

  • CVE-2014-9464
    31Monitor

    SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 2%

    microweber · microweberJan 3, 2015

  • Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file ext

    HighCVSS 7.8No exploitEPSS 0%

    microweber · microweberMay 20, 2020

  • CVE-2022-0913
    30Monitor

    Integer Overflow or Wraparound in microweber/microweber

    HighCVSS 7.5No exploitEPSS 1%

    microweber · microweberMar 11, 2022

  • CVE-2022-0282
    30Monitor

    Cross-site Scripting in microweber/microweber

    HighCVSS 7.5No exploitEPSS 1%

    microweber · microweberJan 20, 2022

  • CVE-2022-0777
    30Monitor

    Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber

    HighCVSS 7.5No exploitEPSS 1%

    microweber · microweberMar 1, 2022