microweber has 3 CVEs on record between 2020 and 2026. 2 were published in the last 90 days. The median CVSS is 5.9 (medium). Most affected products: Administration panel (2), microweber (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
microweber vulnerabilities
CVEs affecting microweber, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-5696Medium· 5.9Reflected Cross-Site Scripting (XSS) in Microweber
Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user int…
CVE-2026-5695High· 8.4Arbitrary file upload vulnerability due to a lack of proper validation in upload forms
Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code rem…
CVE-2020-23136Medium· 5.5Microweber v1.1.18 is affected by no session expiry after log-out.
Microweber v1.1.18 is affected by no session expiry after log-out.