CVE-2014-9464: Microweber

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.

Affected products

Published 2015-01-03. Last modified 2026-06-17.