Microweber
118 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Microweber, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Microweber CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 3 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 2 |
| 2025-08 | 3 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 118 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High28
- Medium86
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Microweber.
- CVE-2026-67617Microweber CMS 2.0.20 Stored XSS via tag_names Parameter4.8
- CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates7.2
- CVE-2026-65694Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController7.5
- CVE-2025-70791Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with adm...6.1
- CVE-2025-70792Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privi...6.1
- CVE-2024-58289Microweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields5.4
- CVE-2025-60954Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including s...8.3
- CVE-2025-51504Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.7.6
- CVE-2025-51502Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.6.1
- CVE-2025-51501Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.6.1
- CVE-2025-51503A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin bro...7.6
- CVE-2025-34076Microweber CMS Authenticated Local File Inclusion via Backup API7.2
- CVE-2025-2214Microweber Settings index.php cross site scripting3.5
- CVE-2024-33297Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function4.7
- CVE-2024-33299Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users4.7
Product grouping is registry-driven, with AI assist and human review. How it works