Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
163042.8%CRITICAL

Related CVEs

63
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-70792Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.MEDIUM6.118.6%Feb 5, 2026
CVE-2025-70791Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.MEDIUM6.118.6%Feb 5, 2026
CVE-2024-58289Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.MEDIUM5.311.7%Dec 11, 2025
CVE-2025-60954Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.HIGH8.333.5%Oct 24, 2025
CVE-2025-51504Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.HIGH7.636.4%Aug 1, 2025
CVE-2025-51502Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.MEDIUM6.149.0%Aug 1, 2025
CVE-2025-51501Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.MEDIUM6.149.4%Aug 1, 2025
CVE-2025-51503A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.HIGH7.635.8%Jul 31, 2025
CVE-2025-34076An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying filesystem. By specifying an absolute file path in the src parameter of the upload request, the server may relocate or delete the target file depending on the web service user’s privileges. The corresponding download endpoint can then be used to retrieve the file contents, effectively enabling local file disclosure. This behavior stems from insufficient validation of user-supplied paths and inadequate restrictions on file access and backup logic.MEDIUM6.167.2%Jul 2, 2025
CVE-2025-2214A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.MEDIUM5.135.7%Mar 12, 2025
CVE-2024-33299Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=usersMEDIUM4.761.2%Jan 10, 2025
CVE-2024-33298Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backupMEDIUM6.153.4%Jan 10, 2025
CVE-2024-33297Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign functionMEDIUM4.761.2%Jan 10, 2025
CVE-2024-40101A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.MEDIUM6.153.6%Aug 6, 2024
CVE-2024-41381microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.MEDIUM6.120.7%Aug 5, 2024
CVE-2024-41380microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.MEDIUM6.120.7%Aug 5, 2024
CVE-2023-6832Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.MEDIUM4.339.7%Dec 15, 2023
CVE-2023-48122An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.HIGH7.553.4%Dec 8, 2023
CVE-2023-6599Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.MEDIUM4.338.4%Dec 8, 2023
CVE-2023-6566Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.MEDIUM6.538.3%Dec 7, 2023