CVE-2022-2368: Microweber

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

Affected products

  • Microweber Microweber: before 1.2.20 (fixed in 1.2.20)

Published 2022-07-11. Last modified 2026-06-17.