Vulnerability index

Browse CVEs

97 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-70791 Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" par… Microweber Patch available Fix from $1,6002026-02-05 MEDIUM 6.1 CVE-2025-70792 Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter i… Microweber Patch available Fix from $1,6002026-02-05 MEDIUM 5.4 CVE-2024-58289 Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user prof… Microweber No fix yet Fix from $1,6002025-12-11 HIGH 8.3 CVE-2025-60954 Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Use… Microweber No fix yet Fix from $1,9502025-10-24 HIGH 7.6 CVE-2025-51504 Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field. Microweber No fix yet Fix from $1,9502025-08-01 MEDIUM 6.1 CVE-2025-51501 Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbit… Microweber No fix yet Fix from $1,6002025-08-01 MEDIUM 6.1 CVE-2025-51502 Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execut… Microweber No fix yet Fix from $1,6002025-08-01 HIGH 7.6 CVE-2025-51503 A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leadin… Microweber Mitigation only Fix from $1,9502025-07-31 HIGH 7.2 CVE-2025-34076 An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenti… Microweber after 1.2.11 Fix from $1,9502025-07-02 MEDIUM 6.1 CVE-2025-2214 A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo… Microweber No fix yet Fix from $1,6002025-03-12 MEDIUM 6.1 CVE-2024-33298 Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup func… Microweber after 2.0.9 Fix from $1,6002025-01-10 MEDIUM 6.1 CVE-2024-40101 A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers t… Microweber after 2.0.15 Fix from $1,6002024-08-06 MEDIUM 6.1 CVE-2024-41381 microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. Microweber No fix yet Fix from $1,6002024-08-05 MEDIUM 6.1 CVE-2024-41380 microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. Microweber No fix yet Fix from $1,6002024-08-05 HIGH 7.5 CVE-2023-48122 An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. Microweber 2.0.4+ Fix from $1,9502023-12-08 MEDIUM 6.5 CVE-2023-6566 Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. Microweber 2.0.0+ Fix from $1,6002023-12-07 HIGH 8.8 CVE-2023-49052 File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i… Microweber Patch available Fix from $1,9502023-11-30 MEDIUM 5.4 CVE-2023-47379 Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. Microweber Patch available Fix from $1,6002023-11-08 HIGH 7.5 CVE-2023-5318 Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. Microweber 2.0+ Fix from $1,9502023-09-30 MEDIUM 6.1 CVE-2023-5244 Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. Microweber 2.0+ Fix from $1,6002023-09-28 MEDIUM 5.4 CVE-2023-3142 Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. Microweber 2.0+ Fix from $1,6002023-06-07 MEDIUM 6.5 CVE-2023-2239 Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4. Microweber 1.3.4+ Fix from $1,6002023-04-22 HIGH 8.8 CVE-2023-2240 Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. Microweber 1.3.4+ Fix from $1,9502023-04-22 MEDIUM 5.4 CVE-2023-1881 Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. Microweber 1.3.3+ Fix from $1,6002023-04-05 CRITICAL 9.8 CVE-2023-1877 Command Injection in GitHub repository microweber/microweber prior to 1.3.3. Microweber 1.3.3+ Fix from $2,3002023-04-05 MEDIUM 6.1 CVE-2021-32856 Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site script… Microweber after 1.2.12 Fix from $1,6002023-02-21 MEDIUM 5.4 CVE-2023-0608 Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. Microweber 1.3.2+ Fix from $1,6002023-02-01 HIGH 7.2 CVE-2022-4732EPSS 38% Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. Microweber after 1.3.1 Fix from $1,9502022-12-27 MEDIUM 6.1 CVE-2022-4647 Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. Microweber after 1.3.1 Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-4617 Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. Microweber after 1.3.1 Fix from $1,6002022-12-21