Weaver vendor intelligence

Weaver Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Weaver products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Weaver KEVs Full KEV feed
Total KEVs
11
Known exploited vulnerabilities affecting Weaver products
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
11
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
Weaver KEV with sensor-observed exploitation activity

The catalog gap matters for Weaver exposure

Eleven of the eleven exploited Weaver CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.

0%
Covered by CISA
100%
Beyond CISA
7
Product families

Attested Weaver CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2016-20097

Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad

E-cology 8.0 High Beyond CISA 14 Aug 2026
CVE-2022-50997

Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp

E-cology 9.0, E-cology 8.0 High Beyond CISA 14 Aug 2026
CVE-2022-4995

Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp

E-cology 9.0 High Beyond CISA 14 Aug 2026
CVE-2026-22679

Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint

E-cology High Beyond CISA 19 Jul 2026
CVE-2022-50992

Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet

E-cology Confirmed Beyond CISA 06 Jul 2026
CVE-2025-34038

Weaver E-cology SQL Injection

E-cology High Beyond CISA 29 Jan 2026
CVE-2022-50993

Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet

E-office High Beyond CISA 30 Apr 2026
CVE-2023-2648

Weaver E-Office uploadify.php unrestricted upload

E-Office High Beyond CISA 05 Jun 2025
CVE-2023-3793

Weaver e-cology HTTP POST Request filelFileDownloadForOutDoc.class sql injection

e-cology High Beyond CISA 20 Jul 2023
CVE-2023-2806

Weaver e-cology API RequestInfoByXml xml external entity reference

e-cology High Beyond CISA 19 May 2023
CVE-2023-2523

Weaver E-Office unrestricted upload

E-Office High Beyond CISA 04 May 2023

Showing 11 of 11 Weaver known exploited vulnerabilities.

Recurring weakness patterns

Unrestricted upload, neutralization, and limitation account for nine mapped occurrences across this Weaver KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.