Microweber

Microweber

118 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.49%
  • Veröffentlicht 01.08.2025 00:00:00
  • Zuletzt bearbeitet 19.08.2025 15:33:07

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

  • EPSS 0.48%
  • Veröffentlicht 31.07.2025 00:00:00
  • Zuletzt bearbeitet 06.08.2025 16:21:09

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 02.07.2025 19:27:03
  • Zuletzt bearbeitet 20.08.2025 03:05:09

An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 11.03.2025 23:31:04
  • Zuletzt bearbeitet 09.07.2025 17:06:31

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of t...

Exploit
  • EPSS 1.11%
  • Veröffentlicht 10.01.2025 20:15:30
  • Zuletzt bearbeitet 03.07.2025 00:40:10

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

Exploit
  • EPSS 0.86%
  • Veröffentlicht 10.01.2025 20:15:30
  • Zuletzt bearbeitet 03.07.2025 00:39:39

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

Exploit
  • EPSS 1.11%
  • Veröffentlicht 10.01.2025 20:15:30
  • Zuletzt bearbeitet 03.07.2025 00:39:11

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

  • EPSS 0.9%
  • Veröffentlicht 06.08.2024 14:16:04
  • Zuletzt bearbeitet 05.07.2026 01:20:12

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 05.08.2024 18:15:32
  • Zuletzt bearbeitet 10.07.2025 15:48:26

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 05.08.2024 17:15:41
  • Zuletzt bearbeitet 10.07.2025 15:48:39

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.