Vulnerabilities > Microweber > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-13 CVE-2023-2014 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.
network
low complexity
microweber CWE-79
4.8
2023-02-28 CVE-2023-1081 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.
network
low complexity
microweber CWE-79
4.8
2023-02-21 CVE-2021-32856 Cross-site Scripting vulnerability in Microweber
Microweber is a drag and drop website builder and content management system.
network
low complexity
microweber CWE-79
6.1
2023-02-01 CVE-2023-0608 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
network
low complexity
microweber CWE-79
5.4
2022-11-25 CVE-2022-0698 Cross-site Scripting vulnerability in Microweber 1.3.1
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
network
low complexity
microweber CWE-79
6.1
2022-07-15 CVE-2021-36461 Unrestricted Upload of File with Dangerous Type vulnerability in Microweber 1.1.3
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
network
low complexity
microweber CWE-434
6.5
2022-07-09 CVE-2022-2353 Cross-Site Request Forgery (CSRF) vulnerability in Microweber
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
network
low complexity
microweber CWE-352
6.1
2022-06-29 CVE-2022-2252 Open Redirect vulnerability in Microweber
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
5.8
2022-06-22 CVE-2022-2174 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
network
microweber CWE-79
4.3
2022-06-20 CVE-2022-2130 Cross-site Scripting vulnerability in Microweber
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
network
microweber CWE-79
4.3