Weaver Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Weaver products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
8
In CISA KEV
0
Beyond CISA KEV
8
Sensor Observed
0
Virtual Patch Available
0
Weaver KEVs Added by Year
8 Weaver KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-22679
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint |
E-cology | High | Not in CISA | 19 Jul 2026 |
|
CVE-2022-50992
Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet |
E-cology | High | Not in CISA | 06 Jul 2026 |
|
CVE-2025-34038
Weaver E-cology SQL Injection |
E-cology | High | Not in CISA | 29 Jan 2026 |
|
CVE-2022-50993
Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet |
E-office | High | Not in CISA | 30 Apr 2026 |
|
CVE-2023-2648
Weaver E-Office uploadify.php unrestricted upload |
E-Office | High | Not in CISA | 05 Jun 2025 |
|
CVE-2023-3793
Weaver e-cology HTTP POST Request filelFileDownloadForOutDoc.class sql injection |
e-cology | High | Not in CISA | 20 Jul 2023 |
|
CVE-2023-2806
Weaver e-cology API RequestInfoByXml xml external entity reference |
e-cology | High | Not in CISA | 19 May 2023 |
|
CVE-2023-2523
Weaver E-Office unrestricted upload |
E-Office | High | Not in CISA | 04 May 2023 |
Common Vulnerability Classes (CWE)
- CWE-434 — Unrestricted Upload of File with Dangerous Type 3
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-306 — Missing Authentication for Critical Function 1
- CWE-611 — Improper Restriction of XML External Entity Reference 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology