Записи typesettercms
14 опубликованных записей вендора typesettercms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2018-6889Proof of concept | An issue was discovered in Typesetter 5.1.typesettercms · typesetter · CWE-94 | Высокая8,8 | — | 6,7 % | 11 февр. 2018 г. |
35Наблюдать | CVE-2022-25523Эксплойта нет | TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.typesettercms · typesetter · CWE-352 | Высокая8,8 | — | 0,6 % | 25 мар. 2022 г. |
33Наблюдать | CVE-2020-25790Proof of concept | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.typesettercms · typesetter · CWE-434 | Высокая7,2 | — | 15,6 % | 19 сент. 2020 г. |
33Наблюдать | CVE-2018-6888Proof of concept | An issue was discovered in Typesetter 5.1.typesettercms · typesetter · CWE-352 | Высокая8,0 | — | 1,9 % | 11 февр. 2018 г. |
24Наблюдать | CVE-2020-19511Эксплойта нет | Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,typesettercms · typesetter · CWE-79 | Средняя6,1 | — | 0,8 % | 21 июн. 2021 г. |
21Наблюдать | CVE-2018-16639Эксплойта нет | Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.typesettercms · typesetter · CWE-79 | Средняя5,4 | — | 0,7 % | 13 мая 2019 г. |
19Наблюдать | CVE-2018-20837Эксплойта нет | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.typesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,7 % | 9 мая 2019 г. |
19Наблюдать | CVE-2020-35126Эксплойта нет | Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.typesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,7 % | 11 дек. 2020 г. |
19Наблюдать | CVE-2018-16625Эксплойта нет | index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.typesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,7 % | 13 мая 2019 г. |
19Наблюдать | CVE-2018-16626Эксплойта нет | index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.typesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,7 % | 13 мая 2019 г. |
19Наблюдать | CVE-2025-71164Эксплойта нет | Typesetter CMS Reflected XSS via Editing.phptypesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,2 % | 14 янв. 2026 г. |
19Наблюдать | CVE-2025-71165Эксплойта нет | Typesetter CMS Reflected XSS via Status.phptypesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,2 % | 14 янв. 2026 г. |
19Наблюдать | CVE-2025-71166Эксплойта нет | Typesetter CMS Reflected XSS via Move Message Handlingtypesettercms · typesetter · CWE-79 | Средняя4,8 | — | 0,2 % | 14 янв. 2026 г. |
17Наблюдать | CVE-2019-20077Эксплойта нет | The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.typesettercms · typesetter · CWE-352 | Средняя4,3 | — | 0,4 % | 5 янв. 2020 г. |
- CVE-2018-688937Наблюдать
An issue was discovered in Typesetter 5.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %typesettercms · typesetter11 февр. 2018 г.
- CVE-2022-2552335Наблюдать
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %typesettercms · typesetter25 мар. 2022 г.
- CVE-2020-2579033Наблюдать
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.
ВысокаяCVSS 7,2Proof of conceptEPSS 16 %typesettercms · typesetter19 сент. 2020 г.
- CVE-2018-688833Наблюдать
An issue was discovered in Typesetter 5.1.
ВысокаяCVSS 8,0Proof of conceptEPSS 2 %typesettercms · typesetter11 февр. 2018 г.
- CVE-2020-1951124Наблюдать
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
СредняяCVSS 6,1Эксплойта нетEPSS 1 %typesettercms · typesetter21 июн. 2021 г.
- CVE-2018-1663921Наблюдать
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %typesettercms · typesetter13 мая 2019 г.
- CVE-2018-2083719Наблюдать
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %typesettercms · typesetter9 мая 2019 г.
- CVE-2020-3512619Наблюдать
Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %typesettercms · typesetter11 дек. 2020 г.
- CVE-2018-1662519Наблюдать
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %typesettercms · typesetter13 мая 2019 г.
- CVE-2018-1662619Наблюдать
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %typesettercms · typesetter13 мая 2019 г.
- CVE-2025-7116419Наблюдать
Typesetter CMS Reflected XSS via Editing.php
СредняяCVSS 4,8Эксплойта нетEPSS 0 %typesettercms · typesetter14 янв. 2026 г.
- CVE-2025-7116519Наблюдать
Typesetter CMS Reflected XSS via Status.php
СредняяCVSS 4,8Эксплойта нетEPSS 0 %typesettercms · typesetter14 янв. 2026 г.
- CVE-2025-7116619Наблюдать
Typesetter CMS Reflected XSS via Move Message Handling
СредняяCVSS 4,8Эксплойта нетEPSS 0 %typesettercms · typesetter14 янв. 2026 г.
- CVE-2019-2007717Наблюдать
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %typesettercms · typesetter5 янв. 2020 г.