Vulnerabilidades em microweber

84 resultados
Análise Vexday

Com 81 CVEs catalogadas, o Microweber apresenta um volume considerável de vulnerabilidades, embora nenhuma esteja atualmente registrada no catálogo KEV da CISA, posicionando-o abaixo da média geral de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que indica fragilidades persistentes na sanitização de entradas e saídas da aplicação. A CVE mais preocupante no momento é CVE-2022-0557, com score EPSS de 0,51, sugerindo probabilidade relevante de exploração — atenção especial é recomendada para ambientes que ainda não aplicaram a correção correspondente. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas 2 provas de conceito públicas reduzem a superfície de risco imediato, mas as 5 vulnerabilidades críticas catalogadas mantêm a necessidade de monitoramento contínuo.

CVE-2022-3242MEDIUMHTML code Injection in template search keyword in microweber/microweberEPSS 1.4%CVE-2022-0913CRITICALInteger Overflow or Wraparound in microweber/microweberEPSS 1.4%CVE-2022-0896HIGHImproper Neutralization of Special Elements Used in a Template Engine in microweber/microweberEPSS 1.4%CVE-2022-0721HIGHInsertion of Sensitive Information Into Debugging Code in microweber/microweberEPSS 1.4%CVE-2022-0282MEDIUMCross-site Scripting in microweber/microweberEPSS 1.4%CVE-2022-0724CRITICALInsecure Storage of Sensitive Information in microweber/microweberEPSS 1.3%CVE-2022-0777HIGHWeak Password Recovery Mechanism for Forgotten Password in microweber/microweberEPSS 1.2%CVE-2022-1555HIGHDOM XSS in microweber ver 1.2.15 in microweber/microweberEPSS 1.2%CVE-2022-1036MEDIUMAble to create an account with long password leads to memory corruption / Integer Overflow in microweber/microweberEPSS 1.2%CVE-2022-0504MEDIUMGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 1.2%CVE-2022-0277MEDIUMIncorrect Permission Assignment for Critical Resource in microweber/microweberEPSS 1.1%CVE-2022-0690HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.1%CVE-2022-0929MEDIUMXSS on dynamic_text module in microweber/microweberEPSS 1.1%CVE-2022-2368MEDIUMAuthentication Bypass by Spoofing in microweber/microweberEPSS 1.1%CVE-2023-5244MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.1%CVE-2022-0689MEDIUMUse multiple time the one-time coupon in microweber/microweberEPSS 1.0%CVE-2022-0560MEDIUMOpen Redirect in microweber/microweberEPSS 1.0%CVE-2022-0961HIGHThe microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweberEPSS 1.0%CVE-2022-1504MEDIUMXSS in /demo/module/?module=HERE in microweber/microweberEPSS 1.0%CVE-2022-2470MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%