📦 Microweber

by Microweber

🔍 What is Microweber?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-1877

CRITICAL CVSS 9.8 Apr 5, 2023

This CVE describes a command injection vulnerability in Microweber CMS versions prior to 1.3.3. Attackers can execute arbitrary operating system commands on the server by injecting malicious input int...

CVE-2022-0895

CRITICAL CVSS 9.8 Mar 10, 2022

CVE-2022-0895 is a static code injection vulnerability in Microweber CMS prior to version 1.3, allowing attackers to inject malicious code into static files, potentially leading to remote code executi...

CVE-2020-23138

CRITICAL CVSS 9.8 Nov 9, 2020

This vulnerability allows attackers to upload malicious PHP files disguised as JPEG images to Microweber's admin panel. Attackers can execute arbitrary code on the web server, potentially compromising...

CVE-2025-60954

HIGH CVSS 8.3 Oct 24, 2025

Microweber CMS 2.0 has weak password requirements that allow users to set extremely simple passwords during password resets, including single-character passwords. This vulnerability affects all Microw...

CVE-2025-51504

HIGH CVSS 7.6 Aug 1, 2025

Microweber CMS 2.0 contains a stored cross-site scripting (XSS) vulnerability in the profile page's last name field. This allows attackers to inject malicious scripts that execute when other users vie...

CVE-2025-34076

HIGH CVSS 7.2 Jul 2, 2025

An authenticated local file inclusion vulnerability in Microweber CMS allows authenticated users to read arbitrary files from the filesystem. Attackers can abuse backup management API endpoints to dis...

CVE-2023-49052

HIGH CVSS 8.8 Nov 30, 2023

This vulnerability allows remote attackers to upload malicious files through Microweber's forms component, leading to arbitrary code execution. It affects Microweber CMS installations running version ...

CVE-2023-5318

HIGH CVSS 7.5 Sep 30, 2023

CVE-2023-5318 involves hard-coded credentials in Microweber CMS versions before 2.0, allowing attackers to gain unauthorized access to affected systems. This affects all users running vulnerable Micro...

CVE-2023-2240

HIGH CVSS 8.8 Apr 22, 2023

This vulnerability allows improper privilege management in Microweber CMS, enabling attackers to escalate privileges or perform unauthorized actions. It affects all Microweber installations prior to v...

CVE-2021-36461

HIGH CVSS 8.8 Jul 15, 2022

Microweber 1.1.3 has an arbitrary file upload vulnerability that allows attackers to upload malicious files disguised as pictures, potentially leading to remote code execution. This affects all Microw...

CVE-2022-0913

HIGH CVSS 7.5 Mar 11, 2022

This integer overflow vulnerability in Microweber CMS allows attackers to cause denial of service or potentially execute arbitrary code by triggering memory corruption. It affects all Microweber insta...

CVE-2022-0777

HIGH CVSS 7.5 Mar 1, 2022

This vulnerability allows attackers to bypass password recovery mechanisms in Microweber CMS, potentially gaining unauthorized access to user accounts. It affects all Microweber installations prior to...

CVE-2022-0666

HIGH CVSS 7.5 Feb 18, 2022

This CVE describes a CRLF injection vulnerability in Microweber CMS that allows attackers to inject carriage return and line feed characters into HTTP headers. This can lead to stack trace exposure, p...

CVE-2022-0281

HIGH CVSS 7.5 Jan 20, 2022

CVE-2022-0281 is an information disclosure vulnerability in Microweber CMS that exposes sensitive information to unauthorized actors. This affects all Microweber installations prior to version 1.2.11,...

CVE-2024-58289

MEDIUM CVSS 5.4 Dec 11, 2025

Microweber 2.0.15 contains a stored cross-site scripting vulnerability in user profile fields that allows authenticated attackers to inject malicious JavaScript. When other users view the attacker's p...

CVE-2025-51501

MEDIUM CVSS 6.1 Aug 1, 2025

This reflected XSS vulnerability in Microweber CMS 2.0 allows attackers to inject malicious JavaScript via the id parameter in the live_edit.module_settings API endpoint. When exploited, this can lead...

CVE-2025-51502

MEDIUM CVSS 6.1 Aug 1, 2025

This vulnerability allows attackers to inject malicious JavaScript via the layout parameter on the admin page creation interface in Microweber CMS. When exploited, it enables arbitrary code execution ...

CVE-2024-33298

MEDIUM CVSS 6.1 Jan 10, 2025

Microweber v2.0.9 contains a cross-site scripting (XSS) vulnerability in the backup creation function that allows remote attackers to inject malicious scripts. This affects administrators who access t...

CVE-2024-40101

MEDIUM CVSS 6.1 Aug 6, 2024

This vulnerability allows unauthenticated remote attackers to inject malicious scripts into the '/search' page of Microweber CMS via the 'keywords' parameter. When a user visits a crafted search URL, ...

CVE-2024-41381

MEDIUM CVSS 6.1 Aug 5, 2024

Microweber 2.0.16 contains a stored cross-site scripting (XSS) vulnerability in the admin.php settings module that allows attackers to inject malicious scripts. This affects administrators who access ...

CVE-2022-0282

MEDIUM CVSS 4.3 Jan 20, 2022

This CVE describes a cross-site scripting (XSS) vulnerability in Microweber CMS versions prior to 1.2.11. Attackers can inject malicious scripts into web pages viewed by other users, potentially steal...