Weaver
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Weaver product.
RSS Feeds for Weaver security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Weaver products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Weaver Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 3 vulnerabilities in Weaver with an average score of 9.0 out of ten. Last year, in 2025 Weaver had 1 security vulnerability published. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 9.03 |
| 2025 | 1 | 0.00 |
| 2024 | 6 | 8.17 |
| 2023 | 7 | 8.86 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 6.30 |
It may take a day or so for new Weaver vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Weaver Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2022-50992 | Apr 30, 2026 |
E-cology <10.52 Arb File Read via XmlRpcServlet (WF Methods)Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC). |
|
| CVE-2022-50993 | Apr 30, 2026 |
Weaver E-office <10.0_20221201 OfficeServer.php upload RCEWeaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC). |
|
| CVE-2026-22679 | Apr 07, 2026 |
Unauth RCE in Weaver E-cology 10.0 (<20260312) dubboApi debugWeaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-03-31 (UTC). |
|
| CVE-2025-34046 | Jun 26, 2025 |
Fanwei E-Office <=9.4 Unauth File Upload (UploadFile.php) RCEAn unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC. |
|
| CVE-2024-48069 | Nov 19, 2024 |
Weaver Ecology v9.* Remote Code Execution via File UploadA vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges |
|
| CVE-2024-48070 | Nov 19, 2024 |
SQL Injection Vulnerability in Weaver Ecology v9*An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges |
|
| CVE-2024-48072 | Nov 19, 2024 |
SQL Injection Vulnerability in Weaver Ecology v9.* via MECAction ServletWeaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1. |
|
| CVE-2024-7704 | Aug 12, 2024 |
Weaver e-cology 8 Source Code Handler Remote Info DisclosureA vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the component Source Code Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2024-3227 | Apr 03, 2024 |
Panwei eoffice OA 9.5 Backend Path Traversal (image_type)A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument image_type leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259072. |
|
| CVE-2023-51892 | Jan 20, 2024 |
Remote code exec via crafted script in Weaver e-Cology FrameworkShellControllerAn issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component. |
|