Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-70791
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" par…
Microweber
Patch available
MEDIUM 6.1
CVE-2025-70792
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter i…
Microweber
Patch available
MEDIUM 5.4
CVE-2024-58289
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user prof…
Microweber
No fix yet
HIGH 8.3
CVE-2025-60954
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Use…
Microweber
No fix yet
HIGH 7.6
CVE-2025-51504
Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.
Microweber
No fix yet
MEDIUM 6.1
CVE-2025-51501
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbit…
Microweber
No fix yet
MEDIUM 6.1
CVE-2025-51502
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execut…
Microweber
No fix yet
HIGH 7.6
CVE-2025-51503
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leadin…
Microweber
Mitigation only
HIGH 7.2
CVE-2025-34076
An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenti…
Microweber
after 1.2.11
MEDIUM 6.1
CVE-2025-2214
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo…
Microweber
No fix yet
MEDIUM 6.1
CVE-2024-33298
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup func…
Microweber
after 2.0.9
MEDIUM 6.1
CVE-2024-40101
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers t…
Microweber
after 2.0.15
MEDIUM 6.1
CVE-2024-41381
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
Microweber
No fix yet
MEDIUM 6.1
CVE-2024-41380
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
Microweber
No fix yet
HIGH 7.5
CVE-2023-48122
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
Microweber
2.0.4+
MEDIUM 6.5
CVE-2023-6566
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
Microweber
2.0.0+
HIGH 8.8
CVE-2023-49052
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…
Microweber
Patch available
MEDIUM 5.4
CVE-2023-47379
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
Microweber
Patch available
HIGH 7.5
CVE-2023-5318
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.
Microweber
2.0+
MEDIUM 6.1
CVE-2023-5244
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.
Microweber
2.0+
MEDIUM 5.4
CVE-2023-3142
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
Microweber
2.0+
MEDIUM 6.5
CVE-2023-2239
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.
Microweber
1.3.4+
HIGH 8.8
CVE-2023-2240
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
Microweber
1.3.4+
MEDIUM 5.4
CVE-2023-1881
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.
Microweber
1.3.3+
CRITICAL 9.8
CVE-2023-1877
Command Injection in GitHub repository microweber/microweber prior to 1.3.3.
Microweber
1.3.3+
MEDIUM 6.1
CVE-2021-32856
Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site script…
Microweber
after 1.2.12
MEDIUM 5.4
CVE-2023-0608
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
1.3.2+
HIGH 7.2
CVE-2022-4732EPSS 38%
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
after 1.3.1
MEDIUM 6.1
CVE-2022-4647
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
after 1.3.1
MEDIUM 6.1
CVE-2022-4617
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
after 1.3.1