microweber Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with microweber products.
Products
- microweber/microweber78 vulnerabilities
- microweber10 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-67617MEDIUM | Microweber CMS 2.0.20 Stored XSS via tag_names ParameterMicroweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer t… CWE-79Aug 3, 2026 | CVSS4.8v4.0 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65693HIGH | Microweber CMS 2.0.20 Server-Side Template Injection via Mail TemplatesMicroweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload executi… CWE-94Jul 24, 2026 | CVSS8.6v4.0 | EPSS0.484% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65694HIGH | Microweber CMS 2.0.20 Path Traversal via ServeStaticFileControllerMicroweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files. | CVSS8.7v4.0 | EPSS2.46% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-58289MEDIUM | Microweber 2.0.15 Stored Cross-Site Scripting via User Profile FieldsMicroweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript. CWE-79Dec 11, 2025 | CVSS5.3v4.0 | EPSS0.255% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Microweber Cross Site Scripting (XSS) vulnerabilitymicroweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. CWE-79Aug 5, 2024 | CVSS-v4.0 | EPSS0.307% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microweber Cross Site Scripting (XSS) vulnerabilitymicroweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. CWE-79Aug 5, 2024 | CVSS-v4.0 | EPSS0.307% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-6832MEDIUM | Business Logic Errors in microweber/microweberBusiness Logic Errors in GitHub repository microweber/microweber prior to 2.0. CWE-840Dec 15, 2023 | CVSS4.3v3.1 | EPSS0.512% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6599MEDIUM | Missing Standardized Error Handling Mechanism in microweber/microweberMissing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0. | CVSS4.3v3.1 | EPSS0.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6566MEDIUM | Business Logic Errors in microweber/microweberBusiness Logic Errors in GitHub repository microweber/microweber prior to 2.0. CWE-840Dec 7, 2023 | CVSS6.5v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5976MEDIUM | Improper Access Control in microweber/microweberImproper Access Control in GitHub repository microweber/microweber prior to 2.0. CWE-284Nov 7, 2023 | CVSS4.3v3.1 | EPSS0.394% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5861MEDIUM | Cross-site Scripting (XSS) - Stored in microweber/microweberCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. CWE-79Oct 31, 2023 | CVSS4.8v3.1 | EPSS0.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5318HIGH | Use of Hard-coded Credentials in microweber/microweberUse of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. CWE-798Sep 30, 2023 | CVSS7.5v3.1 | EPSS0.541% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5244MEDIUM | Cross-site Scripting (XSS) - Reflected in microweber/microweberCross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. | CVSS6.1v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-3142MEDIUM | Cross-site Scripting (XSS) - Stored in microweber/microweberCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. CWE-79Jun 7, 2023 | CVSS5.4v3.1 | EPSS0.346% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2240HIGH | Improper Privilege Management in microweber/microweberImproper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. CWE-269Apr 22, 2023 | CVSS8.8v3.1 | EPSS0.706% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2239MEDIUM | Exposure of Private Personal Information to an Unauthorized Actor in microweber/microweberExposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4. CWE-359Apr 22, 2023 | CVSS6.5v3.1 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2014MEDIUM | Cross-site Scripting (XSS) - Generic in microweber/microweberCross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3. CWE-79Apr 13, 2023 | CVSS4.8v3.1 | EPSS0.484% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1881MEDIUM | Cross-site Scripting (XSS) - Stored in microweber/microweberCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. CWE-79Apr 5, 2023 | CVSS5.4v3.1 | EPSS0.493% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1877CRITICAL | Command Injection in microweber/microweberCommand Injection in GitHub repository microweber/microweber prior to 1.3.3. CWE-77Apr 5, 2023 | CVSS9.8v3.1 | EPSS1.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1081MEDIUM | Cross-site Scripting (XSS) - Stored in microweber/microweberCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. CWE-79Feb 28, 2023 | CVSS4.8v3.1 | EPSS0.434% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-32856MEDIUM | Microweber vulnerable to Cross-site ScriptingMicroweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete. CWE-79Feb 20, 2023 | CVSS6.1v3.1 | EPSS0.626% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-32857MEDIUM | Cockpit vulnerable to Cross-site ScriptingCockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. CWE-79Feb 20, 2023 | CVSS6.1v3.1 | EPSS0.709% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0608MEDIUM | Cross-site Scripting (XSS) - DOM in microweber/microweberCross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. CWE-79Feb 1, 2023 | CVSS5.4v3.1 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4732HIGH | Unrestricted Upload of File with Dangerous Type in microweber/microweberUnrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. CWE-434Dec 24, 2022 | CVSS7.2v3.1 | EPSS38.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4647MEDIUM | Cross-site Scripting (XSS) - Stored in microweber/microweberCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. CWE-79Dec 22, 2022 | CVSS6.1v3.1 | EPSS0.488% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |