Vulnerabilities > Microweber

DATE CVE VULNERABILITY TITLE RISK
2022-03-12 CVE-2022-0926 Cross-site Scripting vulnerability in Microweber
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
network
low complexity
microweber CWE-79
4.8
2022-03-11 CVE-2022-0921 Unrestricted Upload of File with Dangerous Type vulnerability in Microweber
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
local
low complexity
microweber CWE-434
6.7
2022-03-11 CVE-2022-0928 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
network
low complexity
microweber CWE-79
5.4
2022-03-11 CVE-2022-0912 Unrestricted Upload of File with Dangerous Type vulnerability in Microweber
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-434
4.8
2022-03-11 CVE-2022-0913 Integer Overflow or Wraparound vulnerability in Microweber
Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-190
7.5
2022-03-10 CVE-2022-0906 Cross-site Scripting vulnerability in Microweber
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
network
low complexity
microweber CWE-79
4.8
2022-03-10 CVE-2022-0895 Unspecified vulnerability in Microweber
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber
critical
9.8
2022-03-09 CVE-2022-0896 Code Injection vulnerability in Microweber
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-94
8.8
2022-03-04 CVE-2022-0855 Use of Incorrectly-Resolved Name or Reference vulnerability in Microweber Whmcs 0.0.1/0.0.2/0.0.3
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
network
low complexity
microweber CWE-706
6.1
2022-03-01 CVE-2022-0777 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Microweber
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-640
7.5