microweber records
115 published records for vendor microweber.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 9
- With a fix record
- 65.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')57
- CWE-434 Unrestricted Upload of File with Dangerous Type7
- CWE-190 Integer Overflow or Wraparound4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-840 Business Logic Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
115 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2022-0557Proof of concept | OS Command Injection in microweber/microwebermicroweber · microweber · CWE-78 | High7.2 | — | 51.2% | Feb 11, 2022 |
43Plan | CVE-2022-0666Proof of concept | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | High7.5 | — | 44.3% | Feb 18, 2022 |
40Plan | CVE-2023-1877No exploit | Command Injection in microweber/microwebermicroweber · microweber · CWE-77 | Critical9.8 | — | 1.8% | Apr 5, 2023 |
40Plan | CVE-2022-0895No exploit | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Critical9.8 | — | 1.7% | Mar 10, 2022 |
39Monitor | CVE-2022-4732No exploit | Unrestricted Upload of File with Dangerous Type in microweber/microwebermicroweber · microweber · CWE-434 | High7.2 | — | 38.2% | Dec 27, 2022 |
39Monitor | CVE-2020-23138No exploit | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.microweber · microweber · CWE-434 | Critical9.8 | — | 1.3% | Nov 9, 2020 |
39Monitor | CVE-2022-2368No exploit | Authentication Bypass by Spoofing in microweber/microwebermicroweber · microweber · CWE-290 | Critical9.8 | — | 1.2% | Jul 11, 2022 |
38Monitor | CVE-2022-1631Proof of concept | Users Account Pre-Takeover or Users Account Takeover. in microweber/microwebermicroweber · microweber · CWE-284 | High8.8 | — | 8.9% | May 9, 2022 |
36Monitor | CVE-2023-49052Proof of concept | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload fmicroweber · microweber · CWE-434 | High8.8 | — | 2.4% | Nov 30, 2023 |
35Monitor | CVE-2022-33012No exploit | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.microweber · microweber · CWE-74 | High8.8 | — | 1.4% | Nov 22, 2022 |
35Monitor | CVE-2022-0896No exploit | Improper Neutralization of Special Elements Used in a Template Engine in microweber/microwebermicroweber · microweber · CWE-1336 | High8.8 | — | 1.4% | Mar 9, 2022 |
35Monitor | CVE-2021-36461No exploit | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section microweber · microweber · CWE-434 | High8.8 | — | 0.9% | Jul 15, 2022 |
35Monitor | CVE-2018-17104No exploit | An issue was discovered in Microweber 1.0.7.microweber · microweber · CWE-352 | High8.8 | — | 0.8% | Sep 16, 2018 |
35Monitor | CVE-2023-2240No exploit | Improper Privilege Management in microweber/microwebermicroweber · microweber · CWE-269 | High8.8 | — | 0.7% | Apr 21, 2023 |
34Monitor | CVE-2020-13405Proof of concept | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database microweber · microweber · CWE-306 | High7.5 | — | 13.6% | Jul 16, 2020 |
33Monitor | CVE-2020-28337Proof of concept | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execmicroweber · microweber · CWE-22 | High7.2 | — | 16.6% | Feb 15, 2021 |
33Monitor | CVE-2022-0281Proof of concept | Exposure of Sensitive Information to an Unauthorized Actor in microweber/microwebermicroweber · microweber · CWE-200 | High7.5 | — | 10.5% | Jan 20, 2022 |
33Monitor | CVE-2025-60954No exploit | Microweber CMS 2.0 has Weak Password Requirements.microweber · microweber · CWE-521 | High8.3 | — | 0.5% | Oct 24, 2025 |
32Monitor | CVE-2022-0660Proof of concept | Generation of Error Message Containing Sensitive Information in microweber/microwebermicroweber · microweber · CWE-209 | High7.5 | — | 6.9% | Feb 18, 2022 |
32Monitor | CVE-2020-23140No exploit | Microweber 1.1.18 is affected by insufficient session expiration.microweber · microweber · CWE-613 | High8.1 | — | 1.0% | Nov 9, 2020 |
31Monitor | CVE-2014-9464Proof of concept | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commandsmicroweber · microweber · CWE-89 | High7.5 | — | 2.1% | Jan 3, 2015 |
31Monitor | CVE-2020-13241No exploit | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extmicroweber · microweber · CWE-434 | High7.8 | — | 0.5% | May 20, 2020 |
30Monitor | CVE-2022-0913No exploit | Integer Overflow or Wraparound in microweber/microwebermicroweber · microweber · CWE-190 | High7.5 | — | 1.4% | Mar 11, 2022 |
30Monitor | CVE-2022-0282No exploit | Cross-site Scripting in microweber/microwebermicroweber · microweber · CWE-79 | High7.5 | — | 1.4% | Jan 20, 2022 |
30Monitor | CVE-2022-0777No exploit | Weak Password Recovery Mechanism for Forgotten Password in microweber/microwebermicroweber · microweber · CWE-640 | High7.5 | — | 1.2% | Mar 1, 2022 |
- CVE-2022-055743Plan
OS Command Injection in microweber/microweber
HighCVSS 7.2Proof of conceptEPSS 51%microweber · microweberFeb 11, 2022
- CVE-2022-066643Plan
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
HighCVSS 7.5Proof of conceptEPSS 44%microweber · microweberFeb 18, 2022
- CVE-2023-187740Plan
Command Injection in microweber/microweber
CriticalCVSS 9.8No exploitEPSS 2%microweber · microweberApr 5, 2023
- CVE-2022-089540Plan
Static Code Injection in microweber/microweber
CriticalCVSS 9.8No exploitEPSS 2%microweber · microweberMar 10, 2022
- CVE-2022-473239Monitor
Unrestricted Upload of File with Dangerous Type in microweber/microweber
HighCVSS 7.2No exploitEPSS 38%microweber · microweberDec 27, 2022
- CVE-2020-2313839Monitor
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.
CriticalCVSS 9.8No exploitEPSS 1%microweber · microweberNov 9, 2020
- CVE-2022-236839Monitor
Authentication Bypass by Spoofing in microweber/microweber
CriticalCVSS 9.8No exploitEPSS 1%microweber · microweberJul 11, 2022
- CVE-2022-163138Monitor
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
HighCVSS 8.8Proof of conceptEPSS 9%microweber · microweberMay 9, 2022
- CVE-2023-4905236Monitor
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload f
HighCVSS 8.8Proof of conceptEPSS 2%microweber · microweberNov 30, 2023
- CVE-2022-3301235Monitor
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
HighCVSS 8.8No exploitEPSS 1%microweber · microweberNov 22, 2022
- CVE-2022-089635Monitor
Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber
HighCVSS 8.8No exploitEPSS 1%microweber · microweberMar 9, 2022
- CVE-2021-3646135Monitor
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section
HighCVSS 8.8No exploitEPSS 1%microweber · microweberJul 15, 2022
- CVE-2018-1710435Monitor
An issue was discovered in Microweber 1.0.7.
HighCVSS 8.8No exploitEPSS 1%microweber · microweberSep 16, 2018
- CVE-2023-224035Monitor
Improper Privilege Management in microweber/microweber
HighCVSS 8.8No exploitEPSS 1%microweber · microweberApr 21, 2023
- CVE-2020-1340534Monitor
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database
HighCVSS 7.5Proof of conceptEPSS 14%microweber · microweberJul 16, 2020
- CVE-2020-2833733Monitor
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code exec
HighCVSS 7.2Proof of conceptEPSS 17%microweber · microweberFeb 15, 2021
- CVE-2022-028133Monitor
Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber
HighCVSS 7.5Proof of conceptEPSS 10%microweber · microweberJan 20, 2022
- CVE-2025-6095433Monitor
Microweber CMS 2.0 has Weak Password Requirements.
HighCVSS 8.3No exploitEPSS 0%microweber · microweberOct 24, 2025
- CVE-2022-066032Monitor
Generation of Error Message Containing Sensitive Information in microweber/microweber
HighCVSS 7.5Proof of conceptEPSS 7%microweber · microweberFeb 18, 2022
- CVE-2020-2314032Monitor
Microweber 1.1.18 is affected by insufficient session expiration.
HighCVSS 8.1No exploitEPSS 1%microweber · microweberNov 9, 2020
- CVE-2014-946431Monitor
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 2%microweber · microweberJan 3, 2015
- CVE-2020-1324131Monitor
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file ext
HighCVSS 7.8No exploitEPSS 0%microweber · microweberMay 20, 2020
- CVE-2022-091330Monitor
Integer Overflow or Wraparound in microweber/microweber
HighCVSS 7.5No exploitEPSS 1%microweber · microweberMar 11, 2022
- CVE-2022-028230Monitor
Cross-site Scripting in microweber/microweber
HighCVSS 7.5No exploitEPSS 1%microweber · microweberJan 20, 2022
- CVE-2022-077730Monitor
Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber
HighCVSS 7.5No exploitEPSS 1%microweber · microweberMar 1, 2022