Vulnerabilities in Microweber
86 resultsVexday analysis
O Microweber apresenta 2 vulnerabilidades catalogadas, ambas publicadas nos últimos 90 dias, sem registros de exploração ativa (KEV) até o momento. A fraqueza dominante é CWE-434 (upload de arquivo restrito inadequadamente), um vetor clássico de comprometimento, mas a ausência de críticas e atividade explorada em campo sugere risco moderado e controlável com patching oportuno.
CVE-2022-0596MEDIUMImproper Validation of Specified Quantity in Input in microweber/microweberEPSS 0.6%CVE-2022-4617LOWCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.6%CVE-2022-2280MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.6%CVE-2023-5318MEDIUMUse of Hard-coded Credentials in microweber/microweberEPSS 0.5%CVE-2022-2300MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2022-0912MEDIUMUnrestricted Upload of File with Dangerous Type in microweber/microweberEPSS 0.5%CVE-2022-2353MEDIUMCross-Site Request Forgery (CSRF) in microweber/microweberEPSS 0.5%CVE-2023-0608MEDIUMCross-site Scripting (XSS) - DOM in microweber/microweberEPSS 0.5%CVE-2023-6832MEDIUMBusiness Logic Errors in microweber/microweberEPSS 0.5%CVE-2023-2239HIGHExposure of Private Personal Information to an Unauthorized Actor in microweber/microweberEPSS 0.5%CVE-2023-1881HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2023-6599LOWMissing Standardized Error Handling Mechanism in microweber/microweberEPSS 0.5%CVE-2022-4647MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2023-6566MEDIUMBusiness Logic Errors in microweber/microweberEPSS 0.5%CVE-2026-65693HIGHMicroweber CMS 2.0.20 Server-Side Template Injection via Mail TemplatesEPSS 0.5%CVE-2023-2014MEDIUMCross-site Scripting (XSS) - Generic in microweber/microweberEPSS 0.5%CVE-2022-2777MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.4%CVE-2023-5861MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.4%CVE-2023-1081MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.4%CVE-2023-5976MEDIUMImproper Access Control in microweber/microweberEPSS 0.4%