CVE-2025-2214
- EPSS 0.45%
- Veröffentlicht 11.03.2025 23:31:04
- Zuletzt bearbeitet 09.07.2025 17:06:31
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of t...
CVE-2024-33297
- EPSS 1.09%
- Veröffentlicht 10.01.2025 20:15:30
- Zuletzt bearbeitet 03.07.2025 00:40:10
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function
CVE-2024-33298
- EPSS 0.85%
- Veröffentlicht 10.01.2025 20:15:30
- Zuletzt bearbeitet 03.07.2025 00:39:39
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
CVE-2024-33299
- EPSS 1.09%
- Veröffentlicht 10.01.2025 20:15:30
- Zuletzt bearbeitet 03.07.2025 00:39:11
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users
CVE-2024-40101
- EPSS 0.85%
- Veröffentlicht 06.08.2024 14:16:04
- Zuletzt bearbeitet 25.03.2025 14:15:25
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
CVE-2024-41381
- EPSS 0.29%
- Veröffentlicht 05.08.2024 18:15:32
- Zuletzt bearbeitet 10.07.2025 15:48:26
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
CVE-2024-41380
- EPSS 0.29%
- Veröffentlicht 05.08.2024 17:15:41
- Zuletzt bearbeitet 10.07.2025 15:48:39
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
CVE-2023-6832
- EPSS 0.51%
- Veröffentlicht 15.12.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:38
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-48122
- EPSS 0.85%
- Veröffentlicht 08.12.2023 04:15:06
- Zuletzt bearbeitet 21.11.2024 08:31:07
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
CVE-2023-6599
- EPSS 0.49%
- Veröffentlicht 08.12.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:10
Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.