Vulnerabilities
CVE-2022-0913
CRITICALInteger Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0906
MEDIUMUnrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
CVE-2022-0895
HIGHStatic Code Injection in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0896
HIGHImproper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0777
HIGHWeak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0723
HIGHCross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0763
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0762
MEDIUMIncorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0724
CRITICALInsecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0721
HIGHInsertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0719
HIGHCross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0688
CRITICALBusiness Logic Errors in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0690
HIGHCross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0689
MEDIUMUse multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0678
MEDIUMCross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0666
HIGHCRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0660
CRITICALGeneration of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0638
MEDIUMCross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0597
MEDIUMOpen Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0596
MEDIUMImproper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0560
MEDIUMOpen Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0557
HIGHOS Command Injection in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0558
CRITICALCross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0504
MEDIUMGeneration of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0505
MEDIUMCross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0506
HIGHCross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0378
HIGHCross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0379
HIGHCross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0282
MEDIUMCross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0281
HIGHExposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0278
HIGHCross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0277
MEDIUMIncorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
Showing 51 to 82 of 82 vulnerabilities