Technology · Packagist
microweber/microweber (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 106 vulnerabilities in microweber/microweber (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-12198, was published on 15 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About microweber/microweber (Packagist)
Microweber is a content management system and website builder platform written in PHP.
Latest microweber/microweber (Packagist) vulnerabilities
- CVE-2026-12198: Microweber path traversal in thumbnail_img API endpointhighCVSS 7.3EPSS 0.5%
- CVE-2025-70791: Microweber has a Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2025-70792: Microweber Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2025-51501: Microweber has Reflected XSS Vulnerability in the id ParameterlowCVSS 3.1EPSS 0.8%
- CVE-2025-51504: Microweber XSS Vulnerability in the homepage EndpointmediumCVSS 4EPSS 0.5%
- CVE-2025-51502: Microweber has Reflected XSS Vulnerability in the layout ParameterlowCVSS 3.1EPSS 0.8%
- CVE-2025-51503: Microweber Has Stored XSS Vulnerability in User Profile FieldsmediumCVSS 4EPSS 0.5%
- CVE-2025-34076: Microweber CMS API has authenticated local file inclusion vulnerabilitymediumCVSS 4EPSS 2.1%
- CVE-2025-2214: Microweber vulnerable to XSS attack due to insure `group` component in its Settings handlerlowCVSS 3.1EPSS 0.5%
- CVE-2024-33299: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 1.1%
- CVE-2024-33297: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 1.1%
- CVE-2024-33298: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 0.9%
- CVE-2024-40101: Microweber Reflected Cross-site scripting (XSS) vulnerabilitylowCVSS 3.1EPSS 0.9%
- CVE-2024-41380: Microweber Cross Site Scripting (XSS) vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2024-41381: Microweber Cross Site Scripting (XSS) vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2023-6832: Business Logic Errors in microweber/microweberlowCVSS 3EPSS 0.5%
- CVE-2023-48122: Microweber allows a remote attacker to obtain sensitive information via the HTTP GET methodlowCVSS 3.1EPSS 0.9%
- CVE-2023-6599: Microweber missing standardized error handling mechanismlowCVSS 3EPSS 0.5%
- CVE-2023-6566: Microweber Business Logic ErrorslowCVSS 3EPSS 0.5%
- CVE-2023-49052: Microweber file upload vulnerabilitylowCVSS 3.1EPSS 2.4%
- CVE-2023-5976: Microweber Improper Access Control vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2023-47379: Microweber Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-5861: Cross-site Scripting (XSS) in microweber/microweberlowCVSS 3.1EPSS 0.4%
- CVE-2023-5318: Microweber uses hard coded credentialslowCVSS 3EPSS 0.5%
- CVE-2023-5244: Microweber Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 1.1%
Most severe microweber/microweber (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-12198: Microweber path traversal in thumbnail_img API endpointhighCVSS 7.3EPSS 0.5%
- CVE-2025-34076: Microweber CMS API has authenticated local file inclusion vulnerabilitymediumCVSS 4EPSS 2.1%
- CVE-2024-33299: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 1.1%
- CVE-2024-33297: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 1.1%
- CVE-2024-33298: Microweber Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 0.9%
- CVE-2025-51504: Microweber XSS Vulnerability in the homepage EndpointmediumCVSS 4EPSS 0.5%
- CVE-2025-51503: Microweber Has Stored XSS Vulnerability in User Profile FieldsmediumCVSS 4EPSS 0.5%
- CVE-2022-0557: OS Command Injection in MicroweberlowCVSS 3.1EPSS 51.2%
- CVE-2022-4732: Microweber vulnerable to unrestricted malicious uploadslowCVSS 3.1EPSS 38.2%
- CVE-2020-28337: Zip slip in MicroweberlowCVSS 3.1EPSS 16.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/microweber-microweber.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "microweber/microweber (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/microweber-microweber, 28 September 2026.