Weaver Weaver

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Weaver product.

RSS Feeds for Weaver security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Weaver products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Weaver Sorted by Most Security Vulnerabilities since 2018

Weaver E Cology10 vulnerabilities

Weaver E Office8 vulnerabilities

Weaver Office Automation2 vulnerabilities

Weaver Eteams Oa1 vulnerability

By the Year

In 2026 there have been 3 vulnerabilities in Weaver with an average score of 9.0 out of ten. Last year, in 2025 Weaver had 1 security vulnerability published. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 3 9.03
2025 1 0.00
2024 6 8.17
2023 7 8.86
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 2 6.30

It may take a day or so for new Weaver vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Weaver Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2022-50992 Apr 30, 2026
E-cology <10.52 Arb File Read via XmlRpcServlet (WF Methods) Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).
E Cology
CVE-2022-50993 Apr 30, 2026
Weaver E-office <10.0_20221201 OfficeServer.php upload RCE Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC).
E Office
CVE-2026-22679 Apr 07, 2026
Unauth RCE in Weaver E-cology 10.0 (<20260312) dubboApi debug Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-03-31 (UTC).
E Cology
CVE-2025-34046 Jun 26, 2025
Fanwei E-Office <=9.4 Unauth File Upload (UploadFile.php) RCE An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
E Office
CVE-2024-48069 Nov 19, 2024
Weaver Ecology v9.* Remote Code Execution via File Upload A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges
E Cology
CVE-2024-48070 Nov 19, 2024
SQL Injection Vulnerability in Weaver Ecology v9* An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges
E Cology
CVE-2024-48072 Nov 19, 2024
SQL Injection Vulnerability in Weaver Ecology v9.* via MECAction Servlet Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1.
E Cology
CVE-2024-7704 Aug 12, 2024
Weaver e-cology 8 Source Code Handler Remote Info Disclosure A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the component Source Code Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
E Cology
CVE-2024-3227 Apr 03, 2024
Panwei eoffice OA 9.5 Backend Path Traversal (image_type) A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument image_type leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259072.
E Office
CVE-2023-51892 Jan 20, 2024
Remote code exec via crafted script in Weaver e-Cology FrameworkShellController An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.
E Cology
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.