← Vulnerability feed

Vulnerability record · CVE-2022-0281 · published 20 January 2022

CVE-2022-0281: Microweber information exposure vulnerability

Microweber · Microweber

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

7.5 CVSS 3.1 High EPSS 10% · top 4.4% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1877Microweber command injection vulnerabilityCommand Injection in GitHub repository microweber/microweber prior to 1.3.3.EPSS 1.8%9.8CVE-2022-2368Microweber authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.EPSS 1.1%9.8CVE-2022-0895Microweber vulnerabilityStatic Code Injection in GitHub repository microweber/microweber prior to 1.3.EPSS 1.7%9.8CVE-2020-23138Microweber unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…EPSS 1.3%8.8CVE-2023-49052Microweber unrestricted file upload vulnerabilityFile Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…EPSS 2.4%8.8CVE-2023-2240Microweber improper privilege management vulnerabilityImproper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.EPSS 0.71%8.8CVE-2022-33012Microweber injection vulnerabilityMicroweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.EPSS 1.4%8.8CVE-2021-36461Microweber unrestricted file upload vulnerabilityAn Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2022-0281), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.