Vulnerabilities
113 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-70792 +1 in the same advisory: …70791 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-58289 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-60954 | Microweber CMS 2.0 has Weak Password Requirements. Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts. NVD description · AI analysis pending | 8.3 | <1% | PoC ×2 |
| — | |
| CVE-2025-51504 | Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field. Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field. NVD description · AI analysis pending | 7.6 group max | <1% | PoC |
| — | |
| CVE-2025-51503 | A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitr A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers. NVD description · AI analysis pending | 7.6 | <1% |
| — | ||
| CVE-2025-34076 | An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying filesystem. By specifying an absolute file path in the src parameter of the upload request, the server may relocate or delete the target file depending on the web service user’s privileges. The corresponding download endpoint can then be used to retrieve the file contents, effectively enabling local file disclosure. This behavior stems from insufficient validation of user-supplied paths and inadequate restrictions on file access and backup logic. NVD description · AI analysis pending | 6.1 | 2% | PoC ×2 |
| — | |
| CVE-2025-2214 | A vulnerability was found in Microweber 2.0.19. A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-33298 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2024-40101 | A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject ar A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2024-41381 +1 in the same advisory: …41380 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-6832 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2023-48122 +1 in the same advisory: …6599 | An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2023-6566 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-49052 | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the creat File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component. NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — | |
| CVE-2023-47379 | Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-5976 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. Improper Access Control in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2023-5861 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-5318 | Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-5244 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2023-3142 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-2240 +1 in the same advisory: …2239 | Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-2014 | Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3. Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-1877 +1 in the same advisory: …1881 | Command Injection in GitHub repository microweber/microweber prior to 1.3.3. Command Injection in GitHub repository microweber/microweber prior to 1.3.3. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2023-1081 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2021-32856 | Microweber is a drag and drop website builder and content management system. Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-0608 | Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-4732 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. NVD description · AI analysis pending | 7.2 | 38% | PoC |
| — | |
| CVE-2022-4647 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-4617 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-0698 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-33012 | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. NVD description · AI analysis pending | 8.8 | 1% | PoC ×2 |
| — | |
| CVE-2022-3242 +1 in the same advisory: …3245 | Code Injection in GitHub repository microweber/microweber prior to 1.3.2. Code Injection in GitHub repository microweber/microweber prior to 1.3.2. NVD description · AI analysis pending | 6.1 | 2% | PoC |
| — | |
| CVE-2022-2777 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-2470 +1 in the same advisory: …2495 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2021-36461 | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading picture An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-2368 | Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-2353 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch conte Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-2300 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-2280 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |