Loading HuntDB...

Vulnerabilities

CVE-2022-0913

CRITICAL

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

Published Mar 11, 2022

CVE-2022-0906

MEDIUM

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

Published Mar 10, 2022

CVE-2022-0895

HIGH

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

Published Mar 10, 2022

CVE-2022-0896

HIGH

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

Published Mar 09, 2022

CVE-2022-0777

HIGH

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

Published Mar 01, 2022

CVE-2022-0723

HIGH

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.

Published Feb 26, 2022

CVE-2022-0763

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

Published Feb 26, 2022

CVE-2022-0762

MEDIUM

Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

Published Feb 26, 2022

CVE-2022-0724

CRITICAL

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

Published Feb 23, 2022

CVE-2022-0721

HIGH

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

Published Feb 23, 2022

CVE-2022-0719

HIGH

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.

Published Feb 23, 2022

CVE-2022-0688

CRITICAL

Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.

Published Feb 20, 2022

CVE-2022-0690

HIGH

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

Published Feb 19, 2022

CVE-2022-0689

MEDIUM

Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.

Published Feb 19, 2022

CVE-2022-0678

MEDIUM

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

Published Feb 19, 2022

CVE-2022-0666

HIGH

CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.

Published Feb 18, 2022

CVE-2022-0660

CRITICAL

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

Published Feb 18, 2022

CVE-2022-0638

MEDIUM

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

Published Feb 17, 2022

CVE-2022-0597

MEDIUM

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

Published Feb 15, 2022

CVE-2022-0596

MEDIUM

Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.

Published Feb 15, 2022

CVE-2022-0560

MEDIUM

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

Published Feb 11, 2022

CVE-2022-0557

HIGH

OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

Published Feb 11, 2022

CVE-2022-0558

CRITICAL

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

Published Feb 10, 2022

CVE-2022-0504

MEDIUM

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

Published Feb 08, 2022

CVE-2022-0505

MEDIUM

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

Published Feb 08, 2022

CVE-2022-0506

HIGH

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

Published Feb 08, 2022

CVE-2022-0378

HIGH

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

Published Jan 26, 2022

CVE-2022-0379

HIGH

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

Published Jan 26, 2022

CVE-2022-0282

MEDIUM

Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

Published Jan 20, 2022

CVE-2022-0281

HIGH

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

Published Jan 20, 2022

CVE-2022-0278

HIGH

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

Published Jan 20, 2022

CVE-2022-0277

MEDIUM

Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

Published Jan 20, 2022