Vulnerabilities > Microweber

DATE CVE VULNERABILITY TITLE RISK
2022-01-26 CVE-2022-0378 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
4.3
2022-01-26 CVE-2022-0379 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2022-01-20 CVE-2022-0282 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-79
7.5
2022-01-20 CVE-2022-0281 Information Exposure vulnerability in Microweber
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-200
5.0
2022-01-20 CVE-2022-0277 Incorrect Permission Assignment for Critical Resource vulnerability in Microweber
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-732
6.5
2022-01-20 CVE-2022-0278 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
network
microweber CWE-79
3.5
2021-10-19 CVE-2021-33988 Cross-site Scripting vulnerability in Microweber 1.2.7
Cross Site Scripting (XSS).
network
microweber CWE-79
4.3
2021-02-15 CVE-2020-28337 Path Traversal vulnerability in Microweber
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature.
network
low complexity
microweber CWE-22
6.5
2020-11-09 CVE-2020-23140 Insufficient Session Expiration vulnerability in Microweber 1.1.18
Microweber 1.1.18 is affected by insufficient session expiration.
5.8
2020-11-09 CVE-2020-23139 Improper Authentication vulnerability in Microweber 1.1.18
Microweber 1.1.18 is affected by broken authentication and session management.
local
low complexity
microweber CWE-287
2.1