microweber CVE Vulnerabilities & Metrics

Focus on microweber vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About microweber Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with microweber. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total microweber CVEs: 99
Earliest CVE date: 12 May 2014, 14:55 UTC
Latest CVE date: 06 Aug 2024, 14:16 UTC

Latest CVE reference: CVE-2024-40101

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -93.75%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -93.75%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical microweber CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.32

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 48
4.0-6.9 46
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS microweber CVEs

These are the five CVEs with the highest CVSS scores for microweber, sorted by severity first and recency.

All CVEs for microweber

CVE-2024-40101 microweber vulnerability CVSS: 0 06 Aug 2024, 14:16 UTC

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

CVE-2023-6832 microweber vulnerability CVSS: 0 15 Dec 2023, 01:15 UTC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-48122 microweber vulnerability CVSS: 0 08 Dec 2023, 04:15 UTC

An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

CVE-2023-6599 microweber vulnerability CVSS: 0 08 Dec 2023, 00:15 UTC

Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-6566 microweber vulnerability CVSS: 0 07 Dec 2023, 00:15 UTC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-49052 microweber vulnerability CVSS: 0 30 Nov 2023, 07:15 UTC

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

CVE-2023-47379 microweber vulnerability CVSS: 0 08 Nov 2023, 17:15 UTC

Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.

CVE-2023-5976 microweber vulnerability CVSS: 0 07 Nov 2023, 04:24 UTC

Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-5861 microweber vulnerability CVSS: 0 31 Oct 2023, 01:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-5318 microweber vulnerability CVSS: 0 30 Sep 2023, 01:15 UTC

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-5244 microweber vulnerability CVSS: 0 28 Sep 2023, 01:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-3142 microweber vulnerability CVSS: 0 07 Jun 2023, 15:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-2239 microweber vulnerability CVSS: 0 22 Apr 2023, 17:15 UTC

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-2240 microweber vulnerability CVSS: 0 22 Apr 2023, 01:15 UTC

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-2014 microweber vulnerability CVSS: 0 13 Apr 2023, 02:15 UTC

Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-1881 microweber vulnerability CVSS: 0 05 Apr 2023, 17:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-1877 microweber vulnerability CVSS: 0 05 Apr 2023, 17:15 UTC

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-1081 microweber vulnerability CVSS: 0 28 Feb 2023, 02:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2021-32856 microweber vulnerability CVSS: 0 21 Feb 2023, 15:15 UTC

Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete.

CVE-2023-0608 microweber vulnerability CVSS: 0 01 Feb 2023, 06:15 UTC

Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-4732 microweber vulnerability CVSS: 0 27 Dec 2022, 15:15 UTC

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-4647 microweber vulnerability CVSS: 0 22 Dec 2022, 02:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-4617 microweber vulnerability CVSS: 0 21 Dec 2022, 01:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-0698 microweber vulnerability CVSS: 0 25 Nov 2022, 18:15 UTC

Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.

CVE-2022-33012 microweber vulnerability CVSS: 0 22 Nov 2022, 14:15 UTC

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

CVE-2022-3245 microweber vulnerability CVSS: 0 20 Sep 2022, 14:15 UTC

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.

CVE-2022-3242 microweber vulnerability CVSS: 0 20 Sep 2022, 11:15 UTC

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

CVE-2022-2777 microweber vulnerability CVSS: 0 11 Aug 2022, 11:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

CVE-2022-2470 microweber vulnerability CVSS: 0 22 Jul 2022, 15:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-2495 microweber vulnerability CVSS: 0 22 Jul 2022, 04:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2021-36461 microweber vulnerability CVSS: 6.5 15 Jul 2022, 12:15 UTC

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

CVE-2022-2368 microweber vulnerability CVSS: 7.5 11 Jul 2022, 08:15 UTC

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

CVE-2022-2353 microweber vulnerability CVSS: 4.3 09 Jul 2022, 09:15 UTC

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

CVE-2022-2300 microweber vulnerability CVSS: 3.5 04 Jul 2022, 11:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-2280 microweber vulnerability CVSS: 3.5 01 Jul 2022, 09:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-2252 microweber vulnerability CVSS: 5.8 29 Jun 2022, 16:15 UTC

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-2174 microweber vulnerability CVSS: 4.3 22 Jun 2022, 12:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

CVE-2022-2130 microweber vulnerability CVSS: 4.3 20 Jun 2022, 09:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-1631 microweber vulnerability CVSS: 6.8 09 May 2022, 14:15 UTC

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.

CVE-2022-1584 microweber vulnerability CVSS: 4.3 04 May 2022, 18:15 UTC

Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim

CVE-2022-1555 microweber vulnerability CVSS: 4.3 04 May 2022, 09:15 UTC

DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...

CVE-2022-1504 microweber vulnerability CVSS: 4.3 27 Apr 2022, 11:15 UTC

XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.

CVE-2022-1439 microweber vulnerability CVSS: 4.3 22 Apr 2022, 17:15 UTC

Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.

CVE-2022-1036 microweber vulnerability CVSS: 5.0 22 Mar 2022, 13:15 UTC

Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0968 microweber vulnerability CVSS: 4.0 15 Mar 2022, 16:15 UTC

The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0963 microweber vulnerability CVSS: 3.5 15 Mar 2022, 16:15 UTC

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0961 microweber vulnerability CVSS: 4.3 15 Mar 2022, 15:15 UTC

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0954 microweber vulnerability CVSS: 3.5 15 Mar 2022, 12:15 UTC

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0930 microweber vulnerability CVSS: 3.5 12 Mar 2022, 14:15 UTC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0929 microweber vulnerability CVSS: 4.3 12 Mar 2022, 11:15 UTC

XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0926 microweber vulnerability CVSS: 3.5 12 Mar 2022, 10:15 UTC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0921 microweber vulnerability CVSS: 6.5 11 Mar 2022, 18:15 UTC

Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0928 microweber vulnerability CVSS: 3.5 11 Mar 2022, 11:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0913 microweber vulnerability CVSS: 5.0 11 Mar 2022, 10:15 UTC

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0912 microweber vulnerability CVSS: 3.5 11 Mar 2022, 10:15 UTC

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0906 microweber vulnerability CVSS: 3.5 10 Mar 2022, 15:15 UTC

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

CVE-2022-0895 microweber vulnerability CVSS: 7.5 10 Mar 2022, 11:15 UTC

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0896 microweber vulnerability CVSS: 6.8 09 Mar 2022, 12:15 UTC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0855 microweber vulnerability CVSS: 5.8 04 Mar 2022, 19:15 UTC

Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.

CVE-2022-0777 microweber vulnerability CVSS: 5.0 01 Mar 2022, 09:15 UTC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0723 microweber vulnerability CVSS: 3.5 26 Feb 2022, 11:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0763 microweber vulnerability CVSS: 3.5 26 Feb 2022, 10:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0762 microweber vulnerability CVSS: 4.0 26 Feb 2022, 10:15 UTC

Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0724 microweber vulnerability CVSS: 4.0 23 Feb 2022, 11:15 UTC

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0721 microweber vulnerability CVSS: 4.0 23 Feb 2022, 11:15 UTC

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0719 microweber vulnerability CVSS: 3.5 23 Feb 2022, 11:15 UTC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-0688 microweber vulnerability CVSS: 4.0 20 Feb 2022, 15:15 UTC

Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0690 microweber vulnerability CVSS: 4.3 19 Feb 2022, 17:15 UTC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0689 microweber vulnerability CVSS: 5.0 19 Feb 2022, 16:15 UTC

Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0678 microweber vulnerability CVSS: 4.3 19 Feb 2022, 11:15 UTC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0666 microweber vulnerability CVSS: 5.0 18 Feb 2022, 15:15 UTC

CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0660 microweber vulnerability CVSS: 5.0 18 Feb 2022, 11:15 UTC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0638 microweber vulnerability CVSS: 4.3 17 Feb 2022, 17:15 UTC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0597 microweber vulnerability CVSS: 5.8 15 Feb 2022, 14:15 UTC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0596 microweber vulnerability CVSS: 4.0 15 Feb 2022, 14:15 UTC

Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0560 microweber vulnerability CVSS: 5.8 11 Feb 2022, 13:15 UTC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0557 microweber vulnerability CVSS: 9.0 11 Feb 2022, 09:15 UTC

OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0558 microweber vulnerability CVSS: 3.5 10 Feb 2022, 10:15 UTC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0506 microweber vulnerability CVSS: 3.5 08 Feb 2022, 09:15 UTC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0505 microweber vulnerability CVSS: 4.3 08 Feb 2022, 09:15 UTC

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0504 microweber vulnerability CVSS: 4.0 08 Feb 2022, 09:15 UTC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0379 microweber vulnerability CVSS: 3.5 26 Jan 2022, 16:15 UTC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0378 microweber vulnerability CVSS: 4.3 26 Jan 2022, 16:15 UTC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0282 microweber vulnerability CVSS: 5.0 20 Jan 2022, 12:15 UTC

Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0281 microweber vulnerability CVSS: 5.0 20 Jan 2022, 11:15 UTC

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0278 microweber vulnerability CVSS: 3.5 20 Jan 2022, 10:15 UTC

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0277 microweber vulnerability CVSS: 4.0 20 Jan 2022, 10:15 UTC

Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

CVE-2021-33988 microweber vulnerability CVSS: 4.3 19 Oct 2021, 17:15 UTC

Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.

CVE-2020-28337 microweber vulnerability CVSS: 6.5 15 Feb 2021, 20:15 UTC

A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.

CVE-2020-23140 microweber vulnerability CVSS: 5.8 09 Nov 2020, 18:15 UTC

Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.

CVE-2020-23139 microweber vulnerability CVSS: 2.1 09 Nov 2020, 18:15 UTC

Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.

CVE-2020-23138 microweber vulnerability CVSS: 7.5 09 Nov 2020, 18:15 UTC

An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.

CVE-2020-23136 microweber vulnerability CVSS: 2.1 09 Nov 2020, 18:15 UTC

Microweber v1.1.18 is affected by no session expiry after log-out.

CVE-2020-13405 microweber vulnerability CVSS: 5.0 16 Jul 2020, 19:15 UTC

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

CVE-2020-13241 microweber vulnerability CVSS: 7.2 20 May 2020, 19:15 UTC

Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.

CVE-2018-19917 microweber vulnerability CVSS: 4.3 21 Mar 2019, 16:00 UTC

Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.

CVE-2018-1000826 microweber vulnerability CVSS: 4.3 20 Dec 2018, 15:29 UTC

Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.

CVE-2018-17104 microweber vulnerability CVSS: 6.8 16 Sep 2018, 21:29 UTC

An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.

CVE-2014-9464 microweber vulnerability CVSS: 7.5 03 Jan 2015, 22:59 UTC

SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.

CVE-2013-5984 microweber vulnerability CVSS: 6.4 12 May 2014, 14:55 UTC

Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter.