Vulnerability index

Browse CVEs

97 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Microweber MEDIUM 6.1
CVE-2022-0698

Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

No fix yet
Fix from $1,600 2022-11-25
Microweber HIGH 8.8
CVE-2022-33012

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

No fix yet
Fix from $1,950 2022-11-22
Microweber MEDIUM 6.1
CVE-2022-3245

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, inject…

Fix: 1.3.2+
Fix from $1,600 2022-09-20
Microweber MEDIUM 6.1
CVE-2022-3242

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,600 2022-09-20
Microweber MEDIUM 5.4
CVE-2022-2777

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

Fix: 1.3.1+
Fix from $1,600 2022-08-11
Microweber MEDIUM 6.1
CVE-2022-2470

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

Fix: 1.2.21+
Fix from $1,600 2022-07-22
Microweber HIGH 8.8
CVE-2021-36461

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…

No fix yet
Fix from $1,950 2022-07-15
Microweber CRITICAL 9.8
CVE-2022-2368

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

Fix: 1.2.20+
Fix from $2,300 2022-07-11
Microweber MEDIUM 6.1
CVE-2022-2353

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, …

Fix: 1.2.20+
Fix from $1,600 2022-07-09
Microweber MEDIUM 5.4
CVE-2022-2300

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Fix: 1.2.19+
Fix from $1,600 2022-07-04
Microweber MEDIUM 5.4
CVE-2022-2280

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Fix: 1.2.19+
Fix from $1,600 2022-07-01
Microweber MEDIUM 6.1
CVE-2022-2252

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

Fix: 1.2.19+
Fix from $1,600 2022-06-29
Microweber MEDIUM 6.1
CVE-2022-2174

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

Fix: 1.2.18+
Fix from $1,600 2022-06-22
Microweber MEDIUM 6.1
CVE-2022-2130

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

Fix: 1.2.17+
Fix from $1,600 2022-06-20
Microweber HIGH 8.8
CVE-2022-1631EPSS 9%

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th…

Fix: 1.2.15+
Fix from $1,950 2022-05-09
Microweber MEDIUM 6.1
CVE-2022-1584

Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim

Fix: 1.2.16+
Fix from $1,600 2022-05-04
Microweber MEDIUM 6.1
CVE-2022-1555

DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...

Fix: 1.2.16+
Fix from $1,600 2022-05-04
Microweber MEDIUM 6.1
CVE-2022-1504

XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.

Fix: 1.2.15+
Fix from $1,600 2022-04-27
Microweber MEDIUM 6.1
CVE-2022-1439

Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the att…

Fix: 1.2.15+
Fix from $1,600 2022-04-22
Microweber HIGH 7.5
CVE-2022-1036

Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,950 2022-03-22
Microweber MEDIUM 5.5
CVE-2022-0968

The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Ser…

Fix: 1.2.12+
Fix from $1,600 2022-03-15
Microweber MEDIUM 5.4
CVE-2022-0963

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,600 2022-03-15
Microweber MEDIUM 5.5
CVE-2022-0961

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (…

Fix: 1.2.12+
Fix from $1,600 2022-03-15
Microweber MEDIUM 5.4
CVE-2022-0954

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods i…

Fix: 1.2.11+
Fix from $1,600 2022-03-15
Microweber MEDIUM 6.1
CVE-2022-0929

XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

Fix: 1.2.11+
Fix from $1,600 2022-03-12
Microweber MEDIUM 6.7
CVE-2022-0921

Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,600 2022-03-11
Microweber MEDIUM 5.4
CVE-2022-0928

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

Fix: after 1.2.11
Fix from $1,600 2022-03-11
Microweber HIGH 7.5
CVE-2022-0913

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

Fix: after 1.2.11
Fix from $1,950 2022-03-11
Microweber CRITICAL 9.8
CVE-2022-0895

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

Fix: 1.3+
Fix from $2,300 2022-03-10
Microweber HIGH 8.8
CVE-2022-0896

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

Fix: 1.3+
Fix from $1,950 2022-03-09