Vulnerabilities > Microweber > Microweber > 1.0.6

DATE CVE VULNERABILITY TITLE RISK
2022-03-09 CVE-2022-0896 Code Injection vulnerability in Microweber
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
network
microweber CWE-94
6.8
2022-03-01 CVE-2022-0777 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Microweber
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-640
5.0
2022-02-26 CVE-2022-0723 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2022-02-26 CVE-2022-0762 Incorrect Authorization vulnerability in Microweber
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-863
4.3
2022-02-26 CVE-2022-0763 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.
network
microweber CWE-79
3.5
2022-02-23 CVE-2022-0719 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.
network
microweber CWE-79
3.5
2022-02-23 CVE-2022-0721 Unspecified vulnerability in Microweber
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber
4.0
2022-02-23 CVE-2022-0724 Insecure Storage of Sensitive Information vulnerability in Microweber
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-922
4.0
2022-02-20 CVE-2022-0688 Unspecified vulnerability in Microweber
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber
4.0
2022-02-19 CVE-2022-0690 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
4.3