Skip to content
Threat Feed

Vendor

Weaver

5 briefs RSS
high threat

Unauthenticated SQL Injection in Weaver E-cology

Weaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.

E-cology web-application-vulnerability sqli remote-execution
1r 2t 1c
high threat

SQL Injection in Weaver E-cology 8.0

Weaver E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files via the markId parameter.

exploited E-cology 8.0 cve-2016-20097 sql-injection webserver
1r 1t 1c
critical threat

Unauthenticated Remote Code Execution in Weaver E-cology 9.0

Weaver E-cology 9.0 versions prior to 10.52 are vulnerable to unauthenticated arbitrary file upload via the /workrelate/plan/util/uploaderOperate.jsp endpoint, allowing remote code execution.

exploited E-cology 9.0 vulnerability rce file-upload webserver
1r 1t 1c
critical threat

Weaver E-cology Unauthenticated RCE Exploitation

A critical unauthenticated remote code execution vulnerability (CVE-2026-22679) in Weaver E-cology office automation software is being actively exploited to execute system commands and reconnaissance activities on affected servers.

exploited E-cology 10.0 +1 rce weaver-ecology cve-2026-22679 exploitation
2r 2t 1c
critical advisory

Weaver E-office Unauthenticated Arbitrary File Upload Vulnerability

Weaver E-office versions prior to 10.0_20221201 are vulnerable to unauthenticated arbitrary file upload in the OfficeServer.php endpoint, allowing attackers to upload PHP webshells and achieve remote code execution.

E-office cve-2022-50993 file-upload webshell rce
2r 2t 1c