Vulnerability index

Browse CVEs

97 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Microweber MEDIUM 6.1
CVE-2025-70791

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" par…

Patch available
Fix from $1,600 2026-02-05
Microweber MEDIUM 6.1
CVE-2025-70792

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter i…

Patch available
Fix from $1,600 2026-02-05
Microweber MEDIUM 5.4
CVE-2024-58289

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user prof…

No fix yet
Fix from $1,600 2025-12-11
Microweber HIGH 8.3
CVE-2025-60954

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Use…

No fix yet
Fix from $1,950 2025-10-24
Microweber HIGH 7.6
CVE-2025-51504

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

No fix yet
Fix from $1,950 2025-08-01
Microweber MEDIUM 6.1
CVE-2025-51501

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbit…

No fix yet
Fix from $1,600 2025-08-01
Microweber MEDIUM 6.1
CVE-2025-51502

Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execut…

No fix yet
Fix from $1,600 2025-08-01
Microweber HIGH 7.6
CVE-2025-51503

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leadin…

Mitigation only
Fix from $1,950 2025-07-31
Microweber HIGH 7.2
CVE-2025-34076

An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenti…

Fix: after 1.2.11
Fix from $1,950 2025-07-02
Microweber MEDIUM 6.1
CVE-2025-2214

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo…

No fix yet
Fix from $1,600 2025-03-12
Microweber MEDIUM 6.1
CVE-2024-33298

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup func…

Fix: after 2.0.9
Fix from $1,600 2025-01-10
Microweber MEDIUM 6.1
CVE-2024-40101

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers t…

Fix: after 2.0.15
Fix from $1,600 2024-08-06
Microweber MEDIUM 6.1
CVE-2024-41381

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

No fix yet
Fix from $1,600 2024-08-05
Microweber MEDIUM 6.1
CVE-2024-41380

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

No fix yet
Fix from $1,600 2024-08-05
Microweber HIGH 7.5
CVE-2023-48122

An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

Fix: 2.0.4+
Fix from $1,950 2023-12-08
Microweber MEDIUM 6.5
CVE-2023-6566

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

Fix: 2.0.0+
Fix from $1,600 2023-12-07
Microweber HIGH 8.8
CVE-2023-49052

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…

Patch available
Fix from $1,950 2023-11-30
Microweber MEDIUM 5.4
CVE-2023-47379

Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.

Patch available
Fix from $1,600 2023-11-08
Microweber HIGH 7.5
CVE-2023-5318

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

Fix: 2.0+
Fix from $1,950 2023-09-30
Microweber MEDIUM 6.1
CVE-2023-5244

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

Fix: 2.0+
Fix from $1,600 2023-09-28
Microweber MEDIUM 5.4
CVE-2023-3142

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

Fix: 2.0+
Fix from $1,600 2023-06-07
Microweber MEDIUM 6.5
CVE-2023-2239

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

Fix: 1.3.4+
Fix from $1,600 2023-04-22
Microweber HIGH 8.8
CVE-2023-2240

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

Fix: 1.3.4+
Fix from $1,950 2023-04-22
Microweber MEDIUM 5.4
CVE-2023-1881

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

Fix: 1.3.3+
Fix from $1,600 2023-04-05
Microweber CRITICAL 9.8
CVE-2023-1877

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

Fix: 1.3.3+
Fix from $2,300 2023-04-05
Microweber MEDIUM 6.1
CVE-2021-32856

Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site script…

Fix: after 1.2.12
Fix from $1,600 2023-02-21
Microweber MEDIUM 5.4
CVE-2023-0608

Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,600 2023-02-01
Microweber HIGH 7.2
CVE-2022-4732EPSS 38%

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

Fix: after 1.3.1
Fix from $1,950 2022-12-27
Microweber MEDIUM 6.1
CVE-2022-4647

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

Fix: after 1.3.1
Fix from $1,600 2022-12-22
Microweber MEDIUM 6.1
CVE-2022-4617

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

Fix: after 1.3.1
Fix from $1,600 2022-12-21