Textpattern records
30 published records for vendor textpattern.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-7474Proof of concept | An issue was discovered in Textpattern CMS 4.6.2 and earlier.textpattern · textpattern · CWE-89 | Critical9.8 | — | 6.2% | Mar 14, 2018 |
39Monitor | CVE-2020-19510No exploit | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.textpattern · textpattern · CWE-434 | Critical9.8 | — | 1.5% | Jun 21, 2021 |
35Monitor | CVE-2023-24269No exploit | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a textpattern · textpattern · CWE-434 | High8.8 | — | 1.1% | Apr 28, 2023 |
35Monitor | CVE-2023-50038No exploit | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.textpattern · textpattern · CWE-434 | High8.8 | — | 0.8% | Dec 28, 2023 |
35Monitor | CVE-2020-29458No exploit | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.textpattern · textpattern · CWE-352 | High8.8 | — | 0.7% | Dec 2, 2020 |
34Monitor | CVE-2021-44082No exploit | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.textpattern · textpattern · CWE-79 | High8.3 | — | 3.0% | Mar 29, 2022 |
31Monitor | CVE-2010-3205Proof of concept | PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URtextpattern · textpattern · CWE-94 | High7.5 | — | 2.9% | Sep 3, 2010 |
31Monitor | CVE-2006-5615Proof of concept | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exetextpattern · textpattern | High7.5 | — | 2.6% | Oct 30, 2006 |
30Monitor | CVE-2018-1000090No exploit | textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in contetextpattern · textpattern · CWE-611 | High7.5 | — | 1.3% | Mar 13, 2018 |
29Monitor | CVE-2023-36220No exploit | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain accesstextpattern · textpattern · CWE-22 | High7.2 | — | 3.4% | Aug 7, 2023 |
29Monitor | CVE-2023-26852Proof of concept | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uptextpattern · textpattern · CWE-434 | High7.2 | — | 2.0% | Apr 12, 2023 |
27Monitor | CVE-2008-5670No exploit | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to chatextpattern · textpattern · CWE-255 | Medium6.8 | — | 1.2% | Dec 18, 2008 |
26Monitor | CVE-2021-30209No exploit | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veritextpattern · textpattern · CWE-434 | Medium6.5 | — | 0.8% | Apr 15, 2021 |
26Monitor | CVE-2026-30452No exploit | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with ltextpattern · textpattern · CWE-284 | Medium6.5 | — | 0.3% | Apr 21, 2026 |
21Monitor | CVE-2021-28002No exploit | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacketextpattern · textpattern · CWE-79 | Medium5.4 | — | 1.1% | Aug 19, 2021 |
21Monitor | CVE-2021-28001No exploit | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exectextpattern · textpattern · CWE-79 | Medium5.4 | — | 1.0% | Aug 19, 2021 |
21Monitor | CVE-2015-8033No exploit | In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.textpattern · textpattern · CWE-521 | Medium5.3 | — | 0.8% | Aug 14, 2020 |
21Monitor | CVE-2015-8032No exploit | In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.textpattern · textpattern · CWE-269 | Medium5.3 | — | 0.8% | Aug 14, 2020 |
20Monitor | CVE-2008-5669No exploit | index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a longtextpattern · textpattern · CWE-20 | Medium5.0 | — | 1.5% | Dec 18, 2008 |
20Monitor | CVE-2011-3807No exploit | Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatiotextpattern · textpattern · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
20Monitor | CVE-2023-53911No exploit | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpttextpattern · textpattern · CWE-79 | Medium5.1 | — | 0.3% | Dec 17, 2025 |
20Monitor | CVE-2026-32986No exploit | Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injectiontextpattern · textpattern · CWE-79 | Medium5.1 | — | 0.3% | Mar 20, 2026 |
19Monitor | CVE-2021-40658No exploit | Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.textpattern · textpattern · CWE-79 | Medium4.8 | — | 0.6% | Jun 14, 2022 |
19Monitor | CVE-2020-35854No exploit | Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.textpattern · textpattern · CWE-79 | Medium4.8 | — | 0.6% | Jan 26, 2021 |
19Monitor | CVE-2020-23239No exploit | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.textpattern · textpattern · CWE-79 | Medium4.8 | — | 0.5% | Jul 26, 2021 |
- CVE-2018-747441Plan
An issue was discovered in Textpattern CMS 4.6.2 and earlier.
CriticalCVSS 9.8Proof of conceptEPSS 6%textpattern · textpatternMar 14, 2018
- CVE-2020-1951039Monitor
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
CriticalCVSS 9.8No exploitEPSS 1%textpattern · textpatternJun 21, 2021
- CVE-2023-2426935Monitor
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a
HighCVSS 8.8No exploitEPSS 1%textpattern · textpatternApr 28, 2023
- CVE-2023-5003835Monitor
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
HighCVSS 8.8No exploitEPSS 1%textpattern · textpatternDec 28, 2023
- CVE-2020-2945835Monitor
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
HighCVSS 8.8No exploitEPSS 1%textpattern · textpatternDec 2, 2020
- CVE-2021-4408234Monitor
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.
HighCVSS 8.3No exploitEPSS 3%textpattern · textpatternMar 29, 2022
- CVE-2010-320531Monitor
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR
HighCVSS 7.5Proof of conceptEPSS 3%textpattern · textpatternSep 3, 2010
- CVE-2006-561531Monitor
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe
HighCVSS 7.5Proof of conceptEPSS 3%textpattern · textpatternOct 30, 2006
- CVE-2018-100009030Monitor
textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte
HighCVSS 7.5No exploitEPSS 1%textpattern · textpatternMar 13, 2018
- CVE-2023-3622029Monitor
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access
HighCVSS 7.2No exploitEPSS 3%textpattern · textpatternAug 7, 2023
- CVE-2023-2685229Monitor
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up
HighCVSS 7.2Proof of conceptEPSS 2%textpattern · textpatternApr 12, 2023
- CVE-2008-567027Monitor
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha
MediumCVSS 6.8No exploitEPSS 1%textpattern · textpatternDec 18, 2008
- CVE-2021-3020926Monitor
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri
MediumCVSS 6.5No exploitEPSS 1%textpattern · textpatternApr 15, 2021
- CVE-2026-3045226Monitor
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l
MediumCVSS 6.5No exploitEPSS 0%textpattern · textpatternApr 21, 2026
- CVE-2021-2800221Monitor
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke
MediumCVSS 5.4No exploitEPSS 1%textpattern · textpatternAug 19, 2021
- CVE-2021-2800121Monitor
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec
MediumCVSS 5.4No exploitEPSS 1%textpattern · textpatternAug 19, 2021
- CVE-2015-803321Monitor
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
MediumCVSS 5.3No exploitEPSS 1%textpattern · textpatternAug 14, 2020
- CVE-2015-803221Monitor
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
MediumCVSS 5.3No exploitEPSS 1%textpattern · textpatternAug 14, 2020
- CVE-2008-566920Monitor
index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long
MediumCVSS 5.0No exploitEPSS 2%textpattern · textpatternDec 18, 2008
- CVE-2011-380720Monitor
Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio
MediumCVSS 5.0No exploitEPSS 1%textpattern · textpatternSep 23, 2011
- CVE-2023-5391120Monitor
Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt
MediumCVSS 5.1No exploitEPSS 0%textpattern · textpatternDec 17, 2025
- CVE-2026-3298620Monitor
Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
MediumCVSS 5.1No exploitEPSS 0%textpattern · textpatternMar 20, 2026
- CVE-2021-4065819Monitor
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
MediumCVSS 4.8No exploitEPSS 1%textpattern · textpatternJun 14, 2022
- CVE-2020-3585419Monitor
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
MediumCVSS 4.8No exploitEPSS 1%textpattern · textpatternJan 26, 2021
- CVE-2020-2323919Monitor
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
MediumCVSS 4.8No exploitEPSS 1%textpattern · textpatternJul 26, 2021