Microweber operates a small portfolio of web-based content management and business automation platforms—notably Microweber itself and integrations with WHMCS—that occupy a niche but visible position in the vulnerability landscape. The vendor's disclosures center on web-application weaknesses inherent to content generation and user-facing input handling: cross-site scripting, unsafe file uploads, code injection, cross-site request forgery, and integer overflow conditions that reflect the challenges of building extensible, user-editable platforms. Public exploit code has a notable tendency to emerge for vulnerabilities in this vendor's products, likely reflecting their exposure as internet-facing content systems attractive to both defensive researchers and attackers. Defenders deploying these platforms should prioritize timely patching and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microweber over time
Signals from CVEs in this vendor scope (117 CVEs).
117 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0557HIGH OS Command Injection in Packagist microweber/microweber prior to 1.2.11. | Feb 11, 2022 | 7.2 | 64 | NO | YES |
CVE-2022-0666HIGH CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11. | Feb 18, 2022 | 7.5 | 52 | NO | YES |
CVE-2022-4732HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | Dec 27, 2022 | 7.2 | 43 | NO | NO |
CVE-2020-28337HIGH A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To | Feb 15, 2021 | 7.2 | 42 | NO | YES |
CVE-2020-13405HIGH userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request. | Jul 16, 2020 | 7.5 | 42 | NO | YES |
CVE-2022-1631HIGH Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, a | May 9, 2022 | 8.8 | 41 | NO | YES |
CVE-2022-0281HIGH Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. | Jan 20, 2022 | 7.5 | 41 | NO | YES |
CVE-2022-0660HIGH Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. | Feb 18, 2022 | 7.5 | 38 | NO | YES |
CVE-2025-34076HIGH An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/ | Jul 2, 2025 | 7.2 | 35 | NO | YES |
CVE-2025-51501MEDIUM Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript. | Aug 1, 2025 | 6.1 | 32 | NO | YES |
Signals from CVEs in this vendor scope (117 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microweber.
Media articles that mention a CVE ID that affects a product developed by Microweber — matched by CVE ID, not by vendor name.