Vulnerabilities > Microweber > Microweber > 1.0.7

DATE CVE VULNERABILITY TITLE RISK
2023-04-13 CVE-2023-2014 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.
network
low complexity
microweber CWE-79
4.8
2023-02-28 CVE-2023-1081 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.
network
low complexity
microweber CWE-79
4.8
2023-02-21 CVE-2021-32856 Cross-site Scripting vulnerability in Microweber
Microweber is a drag and drop website builder and content management system.
network
low complexity
microweber CWE-79
6.1
2023-02-01 CVE-2023-0608 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
network
low complexity
microweber CWE-79
5.4
2022-07-11 CVE-2022-2368 Authentication Bypass by Spoofing vulnerability in Microweber
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
network
low complexity
microweber CWE-290
critical
9.8
2022-07-09 CVE-2022-2353 Cross-Site Request Forgery (CSRF) vulnerability in Microweber
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
network
low complexity
microweber CWE-352
6.1
2022-07-04 CVE-2022-2300 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
network
microweber CWE-79
3.5
2022-07-01 CVE-2022-2280 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
network
microweber CWE-79
3.5
2022-06-29 CVE-2022-2252 Open Redirect vulnerability in Microweber
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
5.8
2022-06-22 CVE-2022-2174 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
network
microweber CWE-79
4.3