Weaver develops a focused suite of enterprise collaboration and office-automation products—including E-Cology, E-Office, and eTeams OA—that are prominently deployed in organizational environments. Its vulnerability disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the recurring weaknesses center on input-handling flaws including SQL injection, unrestricted file uploads, path traversal, and race conditions that are characteristic of web-facing productivity platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weaver over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2766HIGH A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_ | May 17, 2023 | 7.5 | 65 | NO | YES |
CVE-2023-2648CRITICAL A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation | May 11, 2023 | 9.8 | 57 | NO | YES |
CVE-2026-22679CRITICAL Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpo | Apr 7, 2026 | 9.8 | 52 | NO | NO |
CVE-2025-34038HIGH A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a datab | Jun 24, 2025 | 7.5 | 32 | NO | YES |
CVE-2023-2647HIGH A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroot/inc/utility_all.php of the co | May 11, 2023 | 8.8 | 31 | NO | NO |
CVE-2024-48069CRITICAL A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges | Nov 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-51892CRITICAL An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component. | Jan 20, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-3793CRITICAL A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownloadForOutDoc.class of the componen | Jul 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-48072CRITICAL Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&actio | Nov 19, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-48070CRITICAL An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges | Nov 19, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weaver.
Media articles that mention a CVE ID that affects a product developed by Weaver — matched by CVE ID, not by vendor name.