Записи microweber
115 опубликованных записей вендора microweber.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,9 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 65,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')57
- CWE-434 Unrestricted Upload of File with Dangerous Type7
- CWE-190 Integer Overflow or Wraparound4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-840 Business Logic Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
115 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2022-0557Proof of concept | OS Command Injection in microweber/microwebermicroweber · microweber · CWE-78 | Высокая7,2 | — | 51,2 % | 11 февр. 2022 г. |
43В плане | CVE-2022-0666Proof of concept | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | Высокая7,5 | — | 44,3 % | 18 февр. 2022 г. |
40В плане | CVE-2023-1877Эксплойта нет | Command Injection in microweber/microwebermicroweber · microweber · CWE-77 | Критическая9,8 | — | 1,8 % | 5 апр. 2023 г. |
40В плане | CVE-2022-0895Эксплойта нет | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Критическая9,8 | — | 1,7 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2022-4732Эксплойта нет | Unrestricted Upload of File with Dangerous Type in microweber/microwebermicroweber · microweber · CWE-434 | Высокая7,2 | — | 38,2 % | 27 дек. 2022 г. |
39Наблюдать | CVE-2020-23138Эксплойта нет | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.microweber · microweber · CWE-434 | Критическая9,8 | — | 1,3 % | 9 нояб. 2020 г. |
39Наблюдать | CVE-2022-2368Эксплойта нет | Authentication Bypass by Spoofing in microweber/microwebermicroweber · microweber · CWE-290 | Критическая9,8 | — | 1,2 % | 11 июл. 2022 г. |
38Наблюдать | CVE-2022-1631Proof of concept | Users Account Pre-Takeover or Users Account Takeover. in microweber/microwebermicroweber · microweber · CWE-284 | Высокая8,8 | — | 8,9 % | 9 мая 2022 г. |
36Наблюдать | CVE-2023-49052Proof of concept | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload fmicroweber · microweber · CWE-434 | Высокая8,8 | — | 2,4 % | 30 нояб. 2023 г. |
35Наблюдать | CVE-2022-33012Эксплойта нет | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.microweber · microweber · CWE-74 | Высокая8,8 | — | 1,4 % | 22 нояб. 2022 г. |
35Наблюдать | CVE-2022-0896Эксплойта нет | Improper Neutralization of Special Elements Used in a Template Engine in microweber/microwebermicroweber · microweber · CWE-1336 | Высокая8,8 | — | 1,4 % | 9 мар. 2022 г. |
35Наблюдать | CVE-2021-36461Эксплойта нет | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section microweber · microweber · CWE-434 | Высокая8,8 | — | 0,9 % | 15 июл. 2022 г. |
35Наблюдать | CVE-2018-17104Эксплойта нет | An issue was discovered in Microweber 1.0.7.microweber · microweber · CWE-352 | Высокая8,8 | — | 0,8 % | 16 сент. 2018 г. |
35Наблюдать | CVE-2023-2240Эксплойта нет | Improper Privilege Management in microweber/microwebermicroweber · microweber · CWE-269 | Высокая8,8 | — | 0,7 % | 21 апр. 2023 г. |
34Наблюдать | CVE-2020-13405Proof of concept | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database microweber · microweber · CWE-306 | Высокая7,5 | — | 13,6 % | 16 июл. 2020 г. |
33Наблюдать | CVE-2020-28337Proof of concept | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execmicroweber · microweber · CWE-22 | Высокая7,2 | — | 16,6 % | 15 февр. 2021 г. |
33Наблюдать | CVE-2022-0281Proof of concept | Exposure of Sensitive Information to an Unauthorized Actor in microweber/microwebermicroweber · microweber · CWE-200 | Высокая7,5 | — | 10,5 % | 20 янв. 2022 г. |
33Наблюдать | CVE-2025-60954Эксплойта нет | Microweber CMS 2.0 has Weak Password Requirements.microweber · microweber · CWE-521 | Высокая8,3 | — | 0,5 % | 24 окт. 2025 г. |
32Наблюдать | CVE-2022-0660Proof of concept | Generation of Error Message Containing Sensitive Information in microweber/microwebermicroweber · microweber · CWE-209 | Высокая7,5 | — | 6,9 % | 18 февр. 2022 г. |
32Наблюдать | CVE-2020-23140Эксплойта нет | Microweber 1.1.18 is affected by insufficient session expiration.microweber · microweber · CWE-613 | Высокая8,1 | — | 1,0 % | 9 нояб. 2020 г. |
31Наблюдать | CVE-2014-9464Proof of concept | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commandsmicroweber · microweber · CWE-89 | Высокая7,5 | — | 2,1 % | 3 янв. 2015 г. |
31Наблюдать | CVE-2020-13241Эксплойта нет | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extmicroweber · microweber · CWE-434 | Высокая7,8 | — | 0,5 % | 20 мая 2020 г. |
30Наблюдать | CVE-2022-0913Эксплойта нет | Integer Overflow or Wraparound in microweber/microwebermicroweber · microweber · CWE-190 | Высокая7,5 | — | 1,4 % | 11 мар. 2022 г. |
30Наблюдать | CVE-2022-0282Эксплойта нет | Cross-site Scripting in microweber/microwebermicroweber · microweber · CWE-79 | Высокая7,5 | — | 1,4 % | 20 янв. 2022 г. |
30Наблюдать | CVE-2022-0777Эксплойта нет | Weak Password Recovery Mechanism for Forgotten Password in microweber/microwebermicroweber · microweber · CWE-640 | Высокая7,5 | — | 1,2 % | 1 мар. 2022 г. |
- CVE-2022-055743В плане
OS Command Injection in microweber/microweber
ВысокаяCVSS 7,2Proof of conceptEPSS 51 %microweber · microweber11 февр. 2022 г.
- CVE-2022-066643В плане
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
ВысокаяCVSS 7,5Proof of conceptEPSS 44 %microweber · microweber18 февр. 2022 г.
- CVE-2023-187740В плане
Command Injection in microweber/microweber
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microweber · microweber5 апр. 2023 г.
- CVE-2022-089540В плане
Static Code Injection in microweber/microweber
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microweber · microweber10 мар. 2022 г.
- CVE-2022-473239Наблюдать
Unrestricted Upload of File with Dangerous Type in microweber/microweber
ВысокаяCVSS 7,2Эксплойта нетEPSS 38 %microweber · microweber27 дек. 2022 г.
- CVE-2020-2313839Наблюдать
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microweber · microweber9 нояб. 2020 г.
- CVE-2022-236839Наблюдать
Authentication Bypass by Spoofing in microweber/microweber
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microweber · microweber11 июл. 2022 г.
- CVE-2022-163138Наблюдать
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %microweber · microweber9 мая 2022 г.
- CVE-2023-4905236Наблюдать
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload f
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %microweber · microweber30 нояб. 2023 г.
- CVE-2022-3301235Наблюдать
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microweber · microweber22 нояб. 2022 г.
- CVE-2022-089635Наблюдать
Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microweber · microweber9 мар. 2022 г.
- CVE-2021-3646135Наблюдать
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microweber · microweber15 июл. 2022 г.
- CVE-2018-1710435Наблюдать
An issue was discovered in Microweber 1.0.7.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microweber · microweber16 сент. 2018 г.
- CVE-2023-224035Наблюдать
Improper Privilege Management in microweber/microweber
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microweber · microweber21 апр. 2023 г.
- CVE-2020-1340534Наблюдать
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %microweber · microweber16 июл. 2020 г.
- CVE-2020-2833733Наблюдать
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code exec
ВысокаяCVSS 7,2Proof of conceptEPSS 17 %microweber · microweber15 февр. 2021 г.
- CVE-2022-028133Наблюдать
Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %microweber · microweber20 янв. 2022 г.
- CVE-2025-6095433Наблюдать
Microweber CMS 2.0 has Weak Password Requirements.
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %microweber · microweber24 окт. 2025 г.
- CVE-2022-066032Наблюдать
Generation of Error Message Containing Sensitive Information in microweber/microweber
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %microweber · microweber18 февр. 2022 г.
- CVE-2020-2314032Наблюдать
Microweber 1.1.18 is affected by insufficient session expiration.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %microweber · microweber9 нояб. 2020 г.
- CVE-2014-946431Наблюдать
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %microweber · microweber3 янв. 2015 г.
- CVE-2020-1324131Наблюдать
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file ext
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microweber · microweber20 мая 2020 г.
- CVE-2022-091330Наблюдать
Integer Overflow or Wraparound in microweber/microweber
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microweber · microweber11 мар. 2022 г.
- CVE-2022-028230Наблюдать
Cross-site Scripting in microweber/microweber
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microweber · microweber20 янв. 2022 г.
- CVE-2022-077730Наблюдать
Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microweber · microweber1 мар. 2022 г.