Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microweber Subscribe
Filtered by product Microweber
Total 81 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1081 1 Microweber 1 Microweber 2023-03-03 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.
CVE-2021-32856 1 Microweber 1 Microweber 2023-03-02 N/A 6.1 MEDIUM
Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete.
CVE-2023-0608 1 Microweber 1 Microweber 2023-02-08 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-4732 1 Microweber 1 Microweber 2023-01-05 N/A 7.2 HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-4647 1 Microweber 1 Microweber 2022-12-24 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-4617 1 Microweber 1 Microweber 2022-12-24 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-0698 1 Microweber 1 Microweber 2022-11-30 N/A 6.1 MEDIUM
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
CVE-2022-33012 1 Microweber 1 Microweber 2022-11-28 N/A 8.8 HIGH
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
CVE-2022-1631 1 Microweber 1 Microweber 2022-10-19 6.8 MEDIUM 8.8 HIGH
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.
CVE-2022-3245 1 Microweber 1 Microweber 2022-09-21 N/A 6.1 MEDIUM
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
CVE-2022-3242 1 Microweber 1 Microweber 2022-09-21 N/A 6.1 MEDIUM
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-2777 1 Microweber 1 Microweber 2022-08-15 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.
CVE-2022-2470 1 Microweber 1 Microweber 2022-07-26 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2495 1 Microweber 1 Microweber 2022-07-26 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2021-36461 1 Microweber 1 Microweber 2022-07-19 6.5 MEDIUM 8.8 HIGH
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
CVE-2022-2368 1 Microweber 1 Microweber 2022-07-15 7.5 HIGH 9.8 CRITICAL
Business Logic Errors in GitHub repository microweber/microweber prior to 1.2.20.
CVE-2022-2300 1 Microweber 1 Microweber 2022-07-12 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2280 1 Microweber 1 Microweber 2022-07-08 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2252 1 Microweber 1 Microweber 2022-07-07 5.8 MEDIUM 6.1 MEDIUM
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2174 1 Microweber 1 Microweber 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.