Vulnerabilidades em microweber

84 resultados
Análise Vexday

Com 81 CVEs catalogadas, o Microweber apresenta um volume considerável de vulnerabilidades, embora nenhuma esteja atualmente registrada no catálogo KEV da CISA, posicionando-o abaixo da média geral de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que indica fragilidades persistentes na sanitização de entradas e saídas da aplicação. A CVE mais preocupante no momento é CVE-2022-0557, com score EPSS de 0,51, sugerindo probabilidade relevante de exploração — atenção especial é recomendada para ambientes que ainda não aplicaram a correção correspondente. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas 2 provas de conceito públicas reduzem a superfície de risco imediato, mas as 5 vulnerabilidades críticas catalogadas mantêm a necessidade de monitoramento contínuo.

CVE-2022-0557HIGHOS Command Injection in microweber/microweberEPSS 51.2%CVE-2022-0666HIGHCRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweberEPSS 44.3%CVE-2022-4732MEDIUMUnrestricted Upload of File with Dangerous Type in microweber/microweberEPSS 38.2%CVE-2022-0281HIGHExposure of Sensitive Information to an Unauthorized Actor in microweber/microweberEPSS 12.0%CVE-2022-1631MEDIUMUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweberEPSS 8.8%CVE-2022-0660CRITICALGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 6.9%CVE-2022-0378HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 3.9%CVE-2022-0968HIGHThe microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in microweber/microweberEPSS 3.7%CVE-2022-1439MEDIUMReflected XSS on demo.microweber.org/demo/module/ in microweber/microweberEPSS 3.3%CVE-2022-0954MEDIUMMultiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in microweber/microweberEPSS 3.2%CVE-2022-0597MEDIUMOpen Redirect in microweber/microweberEPSS 3.0%CVE-2022-2130MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 2.9%CVE-2022-2174MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 2.8%CVE-2026-65694HIGHMicroweber CMS 2.0.20 Path Traversal via ServeStaticFileControllerEPSS 2.5%CVE-2022-0928MEDIUMCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 2.4%CVE-2022-0678MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 2.3%CVE-2022-0921HIGHAbusing Backup/Restore feature to achieve Remote Code Execution in microweber/microweberEPSS 2.2%CVE-2022-0963MEDIUMUnrestricted XML Files Leads to Stored XSS in microweber/microweberEPSS 1.9%CVE-2023-1877MEDIUMCommand Injection in microweber/microweberEPSS 1.8%CVE-2022-0895HIGHStatic Code Injection in microweber/microweberEPSS 1.7%