CVE-2022-0379
- EPSS 0.86%
- Veröffentlicht 26.01.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:29
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0282
- EPSS 1.38%
- Veröffentlicht 20.01.2022 12:15:08
- Zuletzt bearbeitet 24.02.2026 19:20:29
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0281
- EPSS 12.01%
- Veröffentlicht 20.01.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:17
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0277
- EPSS 1.12%
- Veröffentlicht 20.01.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:17
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0278
- EPSS 0.73%
- Veröffentlicht 20.01.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:17
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2021-33988
- EPSS 1.06%
- Veröffentlicht 19.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:51
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2020-28337
- EPSS 16.61%
- Veröffentlicht 15.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:36
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of a...
CVE-2020-23136
- EPSS 0.32%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 09.07.2026 00:16:59
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-23138
- EPSS 1.32%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php ex...
CVE-2020-23139
- EPSS 0.31%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.