Vulnerability index

Browse CVEs

97 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-0855 Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4. Whmcs 0.0.4+ Fix from $1,6002022-03-04 HIGH 7.5 CVE-2022-0777 Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3. Microweber 1.3+ Fix from $1,9502022-03-01 MEDIUM 5.4 CVE-2022-0723 Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-26 MEDIUM 6.5 CVE-2022-0721 Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3. Microweber 1.3+ Fix from $1,6002022-02-23 MEDIUM 6.5 CVE-2022-0724 Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3. Microweber 1.3+ Fix from $1,6002022-02-23 MEDIUM 5.4 CVE-2022-0719 Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3. Microweber 1.3+ Fix from $1,6002022-02-23 MEDIUM 6.1 CVE-2022-0690 Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-19 MEDIUM 5.3 CVE-2022-0689 Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-19 MEDIUM 6.1 CVE-2022-0678 Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-19 HIGH 7.5 CVE-2022-0666EPSS 44% CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2… Microweber 1.2.11+ Fix from $1,9502022-02-18 HIGH 7.5 CVE-2022-0660EPSS 7% Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,9502022-02-18 MEDIUM 6.1 CVE-2022-0597 Open Redirect in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-15 MEDIUM 6.1 CVE-2022-0560 Open Redirect in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-11 HIGH 7.2 CVE-2022-0557EPSS 51% OS Command Injection in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,9502022-02-11 MEDIUM 5.4 CVE-2022-0558 Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-10 MEDIUM 6.5 CVE-2022-0504 Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-08 MEDIUM 6.5 CVE-2022-0505 Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-08 MEDIUM 5.4 CVE-2022-0506 Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-02-08 MEDIUM 5.4 CVE-2022-0378 Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-01-26 MEDIUM 5.4 CVE-2022-0379 Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-01-26 HIGH 7.5 CVE-2022-0282 Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. Microweber after 1.2.10 Fix from $1,9502022-01-20 HIGH 7.5 CVE-2022-0281EPSS 12% Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. Microweber after 1.2.10 Fix from $1,9502022-01-20 MEDIUM 6.5 CVE-2022-0277 Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11. Microweber after 1.2.10 Fix from $1,6002022-01-20 MEDIUM 5.4 CVE-2022-0278 Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. Microweber 1.2.11+ Fix from $1,6002022-01-20 MEDIUM 6.1 CVE-2021-33988 Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by I… Microweber No fix yet Fix from $1,6002021-10-19 HIGH 7.2 CVE-2020-28337EPSS 17% A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via… Microweber after 1.1.20 Fix from $1,9502021-02-15 CRITICAL 9.8 CVE-2020-23138 An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio… Microweber Mitigation only Fix from $2,3002020-11-09 HIGH 8.1 CVE-2020-23140 Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessio… Microweber Mitigation only Fix from $1,9502020-11-09 MEDIUM 5.5 CVE-2020-23136 Microweber v1.1.18 is affected by no session expiry after log-out. Microweber Mitigation only Fix from $1,6002020-11-09 MEDIUM 5.5 CVE-2020-23139 Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized … Microweber Mitigation only Fix from $1,6002020-11-09