Show filters
100 Total Results
Displaying 41-50 of 100
Sort by:
Attacker Value
Unknown

CVE-2022-1555

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...
Attacker Value
Unknown

CVE-2022-1504

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
Attacker Value
Unknown

CVE-2022-1439

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.
Attacker Value
Unknown

CVE-2022-1036

Disclosure Date: March 22, 2022 (last updated February 23, 2025)
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
Attacker Value
Unknown

CVE-2022-0968

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.
Attacker Value
Unknown

CVE-2022-0963

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
Attacker Value
Unknown

CVE-2022-0961

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.
Attacker Value
Unknown

CVE-2022-0954

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
Attacker Value
Unknown

CVE-2022-0930

Disclosure Date: March 12, 2022 (last updated February 23, 2025)
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
Attacker Value
Unknown

CVE-2022-0929

Disclosure Date: March 12, 2022 (last updated February 23, 2025)
XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.