Known vulnerabilities in Microweber 1.2.6
Vendor:
Microweber CMS Ltd.
Software:
Microweber
Version:
1.2.6
Software CPE:
cpe:2.3:a:microweber_cms:microweber:*:*:*:*:*:*:*:*
Website:
https://microweber.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU61380 - Unrestricted Upload of File with Dangerous Type CVE-2022-0912 |
CWE-434 | Low | 1.2.11 | 15.03.2022 |
SB2022031517 |
||
| #VU61379 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-0928 |
CWE-79 | Low | 1.2.12 | 15.03.2022 |
SB2022031516 |
||
| #VU60883 - Exposure of sensitive information to an unauthorized actor CVE-2022-0721 |
CWE-200 | Medium | 1.3.0 | 25.02.2022 |
SB2022022519 |
||
| #VU60882 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-0719 |
CWE-79 | Low | 1.3.0 | 25.02.2022 |
SB2022022519 |
||
| #VU57842 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-33988 |
CWE-79 | Low | 1.2.8 | 01.11.2021 |
SB2021110107 |