Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.31% | — | MicroweberAI | 23/9/2026 | 24/9/2026 | Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker… | |
| Aplazada | Media (4.8) | 0.27% | — | Microweber CMSAI | 3/8/2026 | 10/9/2026 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent… | |
| Aplazada | Alta (8.6) | 0.92% | — | Microweber CMSAI | 24/7/2026 | 28/7/2026 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks… | |
| Aplazada | Alta (8.7) | 3.4% | — | Microweber CMSAI | 23/7/2026 | 30/7/2026 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the… | |
| Aplazada | Media (5.5) | 0.53% | — | MicroweberAI | 15/6/2026 | 24/7/2026 | A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.1) | 0.32% | — | Microweber | 5/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the… | |
| Analizada | Media (6.1) | 0.31% | — | Microweber | 5/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the… | |
| Analizada | Media (5.3) | 0.26% | — | Microweber | 11/12/2025 | 17/6/2026 | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies… | |
| Analizada | Alta (8.3) | 0.46% | — | Microweber | 24/10/2025 | 17/6/2026 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts. | |
| Analizada | Alta (7.6) | 0.52% | — | Microweber | 1/8/2025 | 17/6/2026 | Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field. | |
| Analizada | Media (6.1) | 0.80% | — | Microweber | 1/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users. | |
| Analizada | Media (6.1) | 0.80% | — | Microweber | 1/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript. | |
| Analizada | Alta (7.6) | 0.50% | — | Microweber | 31/7/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers. | |
| Analizada | Media (6.1) | 2.2% | — | Microweber | 2/7/2025 | 17/6/2026 | An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying filesystem. By specifying an absolute file… | |
| Analizada | Media (5.1) | 0.51% | — | Microweber | 12/3/2025 | 17/6/2026 | A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipulation of the argument group leads to cross site scripting. The attack may be… | |
| Analizada | Media (4.7) | 1.1% | — | Microweber | 10/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users | |
| Analizada | Media (6.1) | 0.86% | — | Microweber | 10/1/2025 | 17/6/2026 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | |
| Analizada | Media (4.7) | 1.1% | — | Microweber | 10/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function | |
| Modificada | Media (6.1) | 0.90% | — | Microweber | 6/8/2024 | 5/7/2026 | A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter. | |
| Analizada | Media (6.1) | 0.31% | — | Microweber | 5/8/2024 | 17/6/2026 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php. | |
| Analizada | Media (6.1) | 0.31% | — | Microweber | 5/8/2024 | 17/6/2026 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php. | |
| Modificada | Media (4.3) | 0.51% | — | Microweber | 15/12/2023 | 17/6/2026 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Alta (7.5) | 0.85% | — | Microweber | 8/12/2023 | 17/6/2026 | An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. | |
| Modificada | Media (4.3) | 0.49% | — | Microweber | 8/12/2023 | 17/6/2026 | Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (6.5) | 0.49% | — | Microweber | 7/12/2023 | 17/6/2026 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. |