Vulnerabilidades em Microweber

86 resultados
Análise Vexday

O Microweber apresenta 2 vulnerabilidades catalogadas, ambas publicadas nos últimos 90 dias, sem registros de exploração ativa (KEV) até o momento. A fraqueza dominante é CWE-434 (upload de arquivo restrito inadequadamente), um vetor clássico de comprometimento, mas a ausência de críticas e atividade explorada em campo sugere risco moderado e controlável com patching oportuno.

CVE-2022-2252MEDIUMOpen Redirect in microweber/microweberEPSS 0.9%CVE-2022-0688CRITICALBusiness Logic Errors in microweber/microweberEPSS 0.9%CVE-2022-0719HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%CVE-2022-0930HIGHFile upload filter bypass leading to stored XSS in microweber/microweberEPSS 0.9%CVE-2022-0558CRITICALCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.9%CVE-2022-0723HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%CVE-2022-0379HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.9%CVE-2022-1584MEDIUMReflected XSS in microweber/microweberEPSS 0.8%CVE-2022-0926HIGHFile upload filter bypass leading to stored XSS in microweber/microweberEPSS 0.8%CVE-2022-0278HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.7%CVE-2022-3245MEDIUM Code Injection in display of tag title on saving tags in microweber/microweberEPSS 0.7%CVE-2021-32857MEDIUMCockpit vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2023-2240HIGHImproper Privilege Management in microweber/microweberEPSS 0.7%CVE-2022-0505MEDIUMCross-Site Request Forgery (CSRF) in microweber/microweberEPSS 0.7%CVE-2022-2495MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.7%CVE-2022-0762MEDIUMIncorrect Authorization in microweber/microweberEPSS 0.7%CVE-2022-0506HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.6%CVE-2021-32856MEDIUMMicroweber vulnerable to Cross-site ScriptingEPSS 0.6%CVE-2022-0906MEDIUMUnrestricted file upload leads to stored XSS in microweber/microweberEPSS 0.6%CVE-2022-0763MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.6%