Filtered by vendor Microweber Subscriptions
Filtered by product Microweber Subscriptions
Total 110 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-0678 1 Microweber 1 Microweber 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0666 1 Microweber 1 Microweber 2024-11-21 7.5 High
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0660 1 Microweber 1 Microweber 2024-11-21 7.5 High
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0638 1 Microweber 1 Microweber 2024-11-21 4.3 Medium
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0597 1 Microweber 1 Microweber 2024-11-21 6.1 Medium
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0596 1 Microweber 1 Microweber 2024-11-21 4.3 Medium
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0560 1 Microweber 1 Microweber 2024-11-21 6.1 Medium
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0558 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0557 1 Microweber 1 Microweber 2024-11-21 7.2 High
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0506 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0505 1 Microweber 1 Microweber 2024-11-21 6.5 Medium
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0504 1 Microweber 1 Microweber 2024-11-21 6.5 Medium
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0379 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0378 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0282 1 Microweber 1 Microweber 2024-11-21 4.3 Medium
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0281 1 Microweber 1 Microweber 2024-11-21 7.5 High
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0278 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0277 1 Microweber 1 Microweber 2024-11-21 6.5 Medium
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVE-2021-36461 1 Microweber 1 Microweber 2024-11-21 8.8 High
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
CVE-2021-33988 1 Microweber 1 Microweber 2024-11-21 6.1 Medium
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.