CVE-2026-67617
- EPSS 0.16%
- Veröffentlicht 03.08.2026 21:53:26
- Zuletzt bearbeitet 04.08.2026 15:16:40
Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of ...
CVE-2026-65693
- EPSS 0.48%
- Veröffentlicht 24.07.2026 15:33:35
- Zuletzt bearbeitet 28.07.2026 20:37:39
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsa...
CVE-2026-65694
- EPSS 2.46%
- Veröffentlicht 23.07.2026 21:20:29
- Zuletzt bearbeitet 30.07.2026 19:56:33
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers...
CVE-2026-12198
- EPSS 0.53%
- Veröffentlicht 15.06.2026 00:16:43
- Zuletzt bearbeitet 24.07.2026 12:10:00
A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path ...
CVE-2025-70791
- EPSS 0.27%
- Veröffentlicht 05.02.2026 17:16:13
- Zuletzt bearbeitet 10.02.2026 18:56:17
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript ...
CVE-2025-70792
- EPSS 0.27%
- Veröffentlicht 05.02.2026 17:16:13
- Zuletzt bearbeitet 10.02.2026 18:54:33
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code exe...
CVE-2024-58289
- EPSS 0.26%
- Veröffentlicht 11.12.2025 21:34:21
- Zuletzt bearbeitet 12.01.2026 16:15:36
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the pr...
CVE-2025-60954
- EPSS 0.43%
- Veröffentlicht 24.10.2025 00:00:00
- Zuletzt bearbeitet 28.10.2025 14:22:52
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account ...
CVE-2025-51501
- EPSS 0.78%
- Veröffentlicht 01.08.2025 00:00:00
- Zuletzt bearbeitet 19.08.2025 15:36:02
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.
CVE-2025-51502
- EPSS 0.77%
- Veröffentlicht 01.08.2025 00:00:00
- Zuletzt bearbeitet 19.08.2025 15:33:25
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.