Vulnerabilities (CVE)

Filtered by vendor Microweber Subscribe
Filtered by product Microweber
Total 108 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-23140 1 Microweber 1 Microweber 2020-11-20 5.8 MEDIUM 8.1 HIGH
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVE-2020-23138 1 Microweber 1 Microweber 2020-11-20 7.5 HIGH 9.8 CRITICAL
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVE-2020-13241 1 Microweber 1 Microweber 2020-05-22 7.2 HIGH 7.8 HIGH
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
CVE-2018-19917 1 Microweber 1 Microweber 2019-04-24 4.3 MEDIUM 6.1 MEDIUM
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
CVE-2018-1000826 1 Microweber 1 Microweber 2019-01-15 4.3 MEDIUM 6.1 MEDIUM
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.
CVE-2018-17104 1 Microweber 1 Microweber 2018-11-20 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
CVE-2014-9464 1 Microweber 1 Microweber 2015-01-05 7.5 HIGH N/A
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.
CVE-2013-5984 1 Microweber 1 Microweber 2014-05-13 6.4 MEDIUM N/A
Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter.