bitweaver CVE Vulnerabilities & Metrics

Focus on bitweaver vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About bitweaver Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with bitweaver. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total bitweaver CVEs: 10
Earliest CVE date: 20 Dec 2005, 02:03 UTC
Latest CVE date: 24 Mar 2021, 13:15 UTC

Latest CVE reference: CVE-2021-29033

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical bitweaver CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.92

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 10
4.0-6.9 16
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS bitweaver CVEs

These are the five CVEs with the highest CVSS scores for bitweaver, sorted by severity first and recency.

All CVEs for bitweaver

CVE-2021-29033 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit_group.php URI.

CVE-2021-29032 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preferences.php URI.

CVE-2021-29031 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/users_import.php URI.

CVE-2021-29030 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/index.php URI.

CVE-2021-29029 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_personal_page.php URI.

CVE-2021-29028 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user_activity.php URI.

CVE-2021-29027 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php URI.

CVE-2021-29026 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/permissions.php URI.

CVE-2021-29025 bitweaver vulnerability CVSS: 3.5 24 Mar 2021, 13:15 UTC

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.php URI.

CVE-2012-5193 bitweaver vulnerability CVSS: 4.3 13 Nov 2019, 21:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php, (4) days parameter to stats/index.php, (5) login parameter to users/register.php, or (6) highlight parameter.

CVE-2012-5192 bitweaver vulnerability CVSS: 5.0 28 Jan 2014, 00:55 UTC

Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_type parameter.

CVE-2010-5086 bitweaver vulnerability CVSS: 5.0 19 Mar 2012, 18:55 UTC

Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.

CVE-2009-1678 bitweaver vulnerability CVSS: 7.5 18 May 2009, 18:30 UTC

Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.

CVE-2009-1677 bitweaver vulnerability CVSS: 6.5 18 May 2009, 18:30 UTC

Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.

CVE-2008-4337 bitweaver vulnerability CVSS: 4.3 30 Sep 2008, 17:22 UTC

Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to (1) edit.php and (2) list.php in articles/; (3) list_blogs.php and (4) rankings.php in blogs/; (5) calendar/index.php; (6) calendar.php, (7) index.php, and (8) list_events.php in events/; (9) index.php and (10) list_galleries.php in fisheye/; (11) liberty/list_content.php; (12) newsletters/edition.php; (13) pigeonholes/list.php; (14) recommends/index.php; (15) rss/index.php; (16) stars/index.php; (17) users/remind_password.php; (18) wiki/orphan_pages.php; and (19) stats/index.php, different vectors than CVE-2007-0526 and CVE-2005-4379. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2007-6650 bitweaver vulnerability CVSS: 7.5 04 Jan 2008, 11:46 UTC

Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file.

CVE-2007-6651 bitweaver vulnerability CVSS: 5.0 04 Jan 2008, 11:46 UTC

Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.

CVE-2007-6412 bitweaver vulnerability CVSS: 6.8 17 Dec 2007, 18:46 UTC

Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackers to inject arbitrary PHP code via an editcomments action.

CVE-2007-6375 bitweaver vulnerability CVSS: 7.5 15 Dec 2007, 01:46 UTC

Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.

CVE-2007-6374 bitweaver vulnerability CVSS: 4.3 15 Dec 2007, 01:46 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3) wiki/index.php or (4) forums/index.php. NOTE: the error parameter to users/login.php is covered by CVE-2006-3103.

CVE-2007-0526 bitweaver vulnerability CVSS: 4.3 26 Jan 2007, 01:28 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php.

CVE-2006-6923 bitweaver vulnerability CVSS: 7.5 13 Jan 2007, 02:28 UTC

SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter.

CVE-2006-6925 bitweaver vulnerability CVSS: 6.8 13 Jan 2007, 02:28 UTC

Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the message title field when submitting an article to articles/edit.php, (2) the message title field when submitting a blog post to blogs/post.php, or (3) the message description field when editing in the Sandbox in wiki/edit.php.

CVE-2006-6924 bitweaver vulnerability CVSS: 5.0 13 Jan 2007, 02:28 UTC

bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.

CVE-2006-3102 bitweaver vulnerability CVSS: 5.1 21 Jun 2006, 01:02 UTC

Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.

CVE-2006-3104 bitweaver vulnerability CVSS: 5.0 21 Jun 2006, 01:02 UTC

users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.

CVE-2006-3105 bitweaver vulnerability CVSS: 5.0 21 Jun 2006, 01:02 UTC

CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php.

CVE-2006-3103 bitweaver vulnerability CVSS: 4.3 21 Jun 2006, 01:02 UTC

Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.

CVE-2006-1745 bitweaver vulnerability CVSS: 2.6 12 Apr 2006, 22:02 UTC

Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2006-1131 bitweaver vulnerability CVSS: 4.3 10 Mar 2006, 02:02 UTC

Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.

CVE-2005-4380 bitweaver vulnerability CVSS: 7.5 20 Dec 2005, 02:03 UTC

Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.