Vulnerabilities (CVE)

Filtered by vendor Microweber Subscribe
Filtered by product Microweber
Total 99 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0930 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 4.8 MEDIUM
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0963 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 5.4 MEDIUM
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0560 1 Microweber 1 Microweber 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-1631 1 Microweber 1 Microweber 2024-02-28 6.8 MEDIUM 8.8 HIGH
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.
CVE-2022-0723 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0689 1 Microweber 1 Microweber 2024-02-28 5.0 MEDIUM 5.3 MEDIUM
Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0896 1 Microweber 1 Microweber 2024-02-28 6.8 MEDIUM 8.8 HIGH
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0926 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 4.8 MEDIUM
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0690 1 Microweber 1 Microweber 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-2252 1 Microweber 1 Microweber 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-1036 1 Microweber 1 Microweber 2024-02-28 5.0 MEDIUM 7.5 HIGH
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0913 1 Microweber 1 Microweber 2024-02-28 5.0 MEDIUM 7.5 HIGH
Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0921 1 Microweber 1 Microweber 2024-02-28 6.5 MEDIUM 6.7 MEDIUM
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0928 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0719 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0721 1 Microweber 1 Microweber 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0954 1 Microweber 1 Microweber 2024-02-28 3.5 LOW 5.4 MEDIUM
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0282 1 Microweber 1 Microweber 2024-02-28 5.0 MEDIUM 7.5 HIGH
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2021-33988 1 Microweber 1 Microweber 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2022-0281 1 Microweber 1 Microweber 2024-02-28 5.0 MEDIUM 7.5 HIGH
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.