Vulnerabilities > Microweber > Microweber > 1.0.6

DATE CVE VULNERABILITY TITLE RISK
2022-02-08 CVE-2022-0504 Information Exposure Through an Error Message vulnerability in Microweber
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-209
4.0
2022-02-08 CVE-2022-0505 Cross-Site Request Forgery (CSRF) vulnerability in Microweber
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
4.3
2022-02-08 CVE-2022-0506 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2022-01-26 CVE-2022-0378 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
4.3
2022-01-26 CVE-2022-0379 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2022-01-20 CVE-2022-0282 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-79
7.5
2022-01-20 CVE-2022-0281 Information Exposure vulnerability in Microweber
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-200
5.0
2022-01-20 CVE-2022-0277 Incorrect Permission Assignment for Critical Resource vulnerability in Microweber
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-732
6.5
2022-01-20 CVE-2022-0278 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2021-02-15 CVE-2020-28337 Path Traversal vulnerability in Microweber
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature.
network
low complexity
microweber CWE-22
6.5