All 9 CVE vulnerabilities found in microweber, with AI-generated Chinese analysis, references, and POCs.
Vendor: microweber
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-67617 | Microweber CMS 2.0.20 Stored XSS via tag_names Parameter CWE-79 | 4.8 | Medium | 2026-08-03 |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates CWE-94 | 7.2 | High | 2026-07-24 |
| CVE-2026-65694 | Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController CWE-22 | 7.5 | High | 2026-07-23 |
| CVE-2026-12198 | Microweber API Endpoint thumbnail_img userfiles_path path traversal CWE-22 | 7.3 | High | 2026-06-15 |
| CVE-2024-58289 | Microweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields CWE-79 | 5.4AI | MediumAI | 2025-12-11 |
| CVE-2025-2214 | Microweber Settings index.php cross site scripting CWE-79 | 3.5 | Low | 2025-03-11 |
| CVE-2021-32856 | Microweber vulnerable to Cross-site Scripting CWE-79 | 6.1 | Medium | 2023-02-20 |
| CVE-2021-32857 | Cockpit vulnerable to Cross-site Scripting CWE-79 | 6.1 | Medium | 2023-02-20 |
| CVE-2022-0698 | Microweber 跨站脚本漏洞 | 8.2 | - | 2022-11-25 |
All 9 known CVE vulnerabilities affecting microweber with full Chinese analysis, references, and POCs where available.