Vulnerability index

Browse CVEs

97 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Microweber HIGH 7.5
CVE-2020-13405EPSS 14%

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /mo…

Fix: 1.1.20+
Fix from $1,950 2020-07-16
Microweber HIGH 7.8
CVE-2020-13241

Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (u…

No fix yet
Fix from $1,950 2020-05-20
Microweber MEDIUM 6.1
CVE-2018-19917

Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.

No fix yet
Fix from $1,600 2019-03-21
Microweber MEDIUM 6.1
CVE-2018-1000826

Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScri…

Fix: after 1.0.7
Fix from $1,600 2018-12-20
Microweber HIGH 8.8
CVE-2018-17104

An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.

Patch available
Fix from $1,950 2018-09-16
Microweber HIGH 7.5
CVE-2014-9464

SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the …

Fix: after 0.95
Fix from $1,950 2015-01-03
Microweber MEDIUM 6.4
CVE-2013-5984

Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary…

Fix: after 0.8
Fix from $1,600 2014-05-12