ZeroHour

Vulnerabilities

113 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-70792
+1 in the same advisory: …70791
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19.

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2024-58289
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields.

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.

NVD description · AI analysis pending
5.3<1% PoC
  • microweber microweber
CVE-2025-60954
Microweber CMS 2.0 has Weak Password Requirements.

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

NVD description · AI analysis pending
8.3<1% PoC ×2
  • microweber microweber
CVE-2025-51504
+2 in the same advisory: …51501 …51502
Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

NVD description · AI analysis pending
7.6
group max
<1% PoC
  • microweber microweber
CVE-2025-51503
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitr

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

NVD description · AI analysis pending
7.6<1%
  • microweber microweber
CVE-2025-34076
An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API.

An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying filesystem. By specifying an absolute file path in the src parameter of the upload request, the server may relocate or delete the target file depending on the web service user’s privileges. The corresponding download endpoint can then be used to retrieve the file contents, effectively enabling local file disclosure. This behavior stems from insufficient validation of user-supplied paths and inadequate restrictions on file access and backup logic.

NVD description · AI analysis pending
6.12% PoC ×2
  • microweber microweber
CVE-2025-2214
A vulnerability was found in Microweber 2.0.19.

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1<1% PoC
  • microweber microweber
CVE-2024-33298
+2 in the same advisory: …33299 …33297
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • microweber microweber
CVE-2024-40101
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject ar

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

NVD description · AI analysis pending
6.1<1%
  • microweber microweber
CVE-2024-41381
+1 in the same advisory: …41380
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2023-6832
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
4.3<1% PoC
  • microweber microweber
CVE-2023-48122
+1 in the same advisory: …6599
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • microweber microweber
CVE-2023-6566
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
6.5<1% PoC
  • microweber microweber
CVE-2023-49052
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the creat

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

NVD description · AI analysis pending
8.82% PoC ×2
  • microweber microweber
CVE-2023-47379
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.

Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.

NVD description · AI analysis pending
5.4<1%
  • microweber microweber
CVE-2023-5976
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
4.3<1% PoC
  • microweber microweber
CVE-2023-5861
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
4.8<1% PoC
  • microweber microweber
CVE-2023-5318
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
7.5<1%
  • microweber microweber
CVE-2023-5244
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
6.11%
  • microweber microweber
CVE-2023-3142
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

NVD description · AI analysis pending
5.4<1% PoC
  • microweber microweber
CVE-2023-2240
+1 in the same advisory: …2239
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

NVD description · AI analysis pending
8.8
group max
<1%
  • microweber microweber
CVE-2023-2014
Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.

Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.

NVD description · AI analysis pending
4.8<1% PoC
  • microweber microweber
CVE-2023-1877
+1 in the same advisory: …1881
Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • microweber microweber
CVE-2023-1081
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

NVD description · AI analysis pending
4.8<1%
  • microweber microweber
CVE-2021-32856
Microweber is a drag and drop website builder and content management system.

Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2023-0608
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.

Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.

NVD description · AI analysis pending
5.4<1% PoC
  • microweber microweber
CVE-2022-4732
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

NVD description · AI analysis pending
7.238% PoC
  • microweber microweber
CVE-2022-4647
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

NVD description · AI analysis pending
6.1<1%
  • microweber microweber
CVE-2022-4617
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2022-0698
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2022-33012
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

NVD description · AI analysis pending
8.81% PoC ×2
  • microweber microweber
CVE-2022-3242
+1 in the same advisory: …3245
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

NVD description · AI analysis pending
6.12% PoC
  • microweber microweber
CVE-2022-2777
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

NVD description · AI analysis pending
5.4<1% PoC
  • microweber microweber
CVE-2022-2470
+1 in the same advisory: …2495
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • microweber microweber
CVE-2021-36461
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading picture

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

NVD description · AI analysis pending
8.8<1% PoC
  • microweber microweber
CVE-2022-2368
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

NVD description · AI analysis pending
9.81% PoC
  • microweber microweber
CVE-2022-2353
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch conte

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

NVD description · AI analysis pending
6.1<1% PoC
  • microweber microweber
CVE-2022-2300
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

NVD description · AI analysis pending
5.4<1% PoC
  • microweber microweber
CVE-2022-2280
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

NVD description · AI analysis pending
5.4<1% PoC
  • microweber microweber