Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Microweber MEDIUM 5.4
CVE-2024-58289

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user prof…

No fix yet
Fix from $1,600 2025-12-11
Microweber HIGH 8.3
CVE-2025-60954

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Use…

No fix yet
Fix from $1,950 2025-10-24
Microweber HIGH 7.6
CVE-2025-51504

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

No fix yet
Fix from $1,950 2025-08-01
Microweber MEDIUM 6.1
CVE-2025-51501

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbit…

No fix yet
Fix from $1,600 2025-08-01
Microweber MEDIUM 6.1
CVE-2025-51502

Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execut…

No fix yet
Fix from $1,600 2025-08-01
Microweber HIGH 7.6
CVE-2025-51503

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leadin…

Mitigation only
Fix from $1,950 2025-07-31
Microweber MEDIUM 6.1
CVE-2025-2214

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo…

No fix yet
Fix from $1,600 2025-03-12
Microweber MEDIUM 6.1
CVE-2024-41381

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

No fix yet
Fix from $1,600 2024-08-05
Microweber MEDIUM 6.1
CVE-2024-41380

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

No fix yet
Fix from $1,600 2024-08-05
Microweber MEDIUM 6.1
CVE-2022-0698

Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

No fix yet
Fix from $1,600 2022-11-25
Microweber HIGH 8.8
CVE-2022-33012

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

No fix yet
Fix from $1,950 2022-11-22
Microweber HIGH 8.8
CVE-2021-36461

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…

No fix yet
Fix from $1,950 2022-07-15
Microweber MEDIUM 6.1
CVE-2021-33988

Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by I…

No fix yet
Fix from $1,600 2021-10-19
Microweber CRITICAL 9.8
CVE-2020-23138

An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…

Mitigation only
Fix from $2,300 2020-11-09
Microweber HIGH 8.1
CVE-2020-23140

Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessio…

Mitigation only
Fix from $1,950 2020-11-09
Microweber MEDIUM 5.5
CVE-2020-23136

Microweber v1.1.18 is affected by no session expiry after log-out.

Mitigation only
Fix from $1,600 2020-11-09
Microweber MEDIUM 5.5
CVE-2020-23139

Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized …

Mitigation only
Fix from $1,600 2020-11-09
Microweber HIGH 7.8
CVE-2020-13241

Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (u…

No fix yet
Fix from $1,950 2020-05-20
Microweber MEDIUM 6.1
CVE-2018-19917

Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.

No fix yet
Fix from $1,600 2019-03-21