Weaver
Weaver E-cology: vulnerabilidades y CVE
Weaver E-cology tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-25776 | Alta (8.7) | 0.36% | — | 18 sept 2026 | Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile… |
| CVE-2022-50997 | Alta (8.7) | 0.62% | — | 11 ago 2026 | Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by… |
| CVE-2016-20097 | Alta (8.7) | 0.63% | — | 11 ago 2026 | Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the… |
| CVE-2022-50992 | Alta (8.7) | 0.70% | — | 30 abr 2026 | Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary… |
| CVE-2026-22679 | Crítica (9.3) | 20% | — | 7 abr 2026 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute… |
| CVE-2025-34038 | Alta (8.7) | 2.1% | — | 24 jun 2025 | A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a database query within the… |
| CVE-2024-48072 | Crítica (9.8) | 0.45% | — | 19 nov 2024 | Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component… |
| CVE-2024-48070 | Crítica (9.8) | 0.72% | — | 19 nov 2024 | An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges |
| CVE-2024-48069 | Crítica (9.8) | 0.41% | — | 19 nov 2024 | A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges |
| CVE-2024-48071 | Media (6.5) | 0.87% | — | 19 nov 2024 | E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to permanently deny service. |
| CVE-2024-7704 | Media (6.9) | 0.78% | — | 12 ago 2024 | A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the component Source Code Handler. The… |
| CVE-2023-51892 | Crítica (9.8) | 0.98% | — | 20 ene 2024 | An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component. |
| CVE-2023-3793 | Crítica (9.8) | 0.49% | — | 20 jul 2023 | A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownloadForOutDoc.class of the component HTTP POST Request Handler. The… |
| CVE-2023-2806 | Alta (8.8) | 0.98% | — | 19 may 2023 | A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity… |
| CVE-2019-10272 | Media (6.1) | 0.69% | — | 30 abr 2019 | An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isintervenor parameter, as demonstrated by the %0aSet-cookie: substring. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.