Skip to content
Noroxi

Textpattern records

30 published records for vendor textpattern.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

30 records
  • An issue was discovered in Textpattern CMS 4.6.2 and earlier.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    textpattern · textpatternMar 14, 2018

  • Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    textpattern · textpatternJun 21, 2021

  • An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a

    HighCVSS 8.8No exploitEPSS 1%

    textpattern · textpatternApr 28, 2023

  • There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

    HighCVSS 8.8No exploitEPSS 1%

    textpattern · textpatternDec 28, 2023

  • Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

    HighCVSS 8.8No exploitEPSS 1%

    textpattern · textpatternDec 2, 2020

  • textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.

    HighCVSS 8.3No exploitEPSS 3%

    textpattern · textpatternMar 29, 2022

  • CVE-2010-3205
    31Monitor

    PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR

    HighCVSS 7.5Proof of conceptEPSS 3%

    textpattern · textpatternSep 3, 2010

  • CVE-2006-5615
    31Monitor

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe

    HighCVSS 7.5Proof of conceptEPSS 3%

    textpattern · textpatternOct 30, 2006

  • textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte

    HighCVSS 7.5No exploitEPSS 1%

    textpattern · textpatternMar 13, 2018

  • Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access

    HighCVSS 7.2No exploitEPSS 3%

    textpattern · textpatternAug 7, 2023

  • An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up

    HighCVSS 7.2Proof of conceptEPSS 2%

    textpattern · textpatternApr 12, 2023

  • CVE-2008-5670
    27Monitor

    Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha

    MediumCVSS 6.8No exploitEPSS 1%

    textpattern · textpatternDec 18, 2008

  • Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri

    MediumCVSS 6.5No exploitEPSS 1%

    textpattern · textpatternApr 15, 2021

  • Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l

    MediumCVSS 6.5No exploitEPSS 0%

    textpattern · textpatternApr 21, 2026

  • A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke

    MediumCVSS 5.4No exploitEPSS 1%

    textpattern · textpatternAug 19, 2021

  • A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec

    MediumCVSS 5.4No exploitEPSS 1%

    textpattern · textpatternAug 19, 2021

  • CVE-2015-8033
    21Monitor

    In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

    MediumCVSS 5.3No exploitEPSS 1%

    textpattern · textpatternAug 14, 2020

  • CVE-2015-8032
    21Monitor

    In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

    MediumCVSS 5.3No exploitEPSS 1%

    textpattern · textpatternAug 14, 2020

  • CVE-2008-5669
    20Monitor

    index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long

    MediumCVSS 5.0No exploitEPSS 2%

    textpattern · textpatternDec 18, 2008

  • CVE-2011-3807
    20Monitor

    Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio

    MediumCVSS 5.0No exploitEPSS 1%

    textpattern · textpatternSep 23, 2011

  • Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

    MediumCVSS 5.1No exploitEPSS 0%

    textpattern · textpatternDec 17, 2025

  • Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

    MediumCVSS 5.1No exploitEPSS 0%

    textpattern · textpatternMar 20, 2026

  • Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

    MediumCVSS 4.8No exploitEPSS 1%

    textpattern · textpatternJun 14, 2022

  • Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

    MediumCVSS 4.8No exploitEPSS 1%

    textpattern · textpatternJan 26, 2021

  • Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

    MediumCVSS 4.8No exploitEPSS 1%

    textpattern · textpatternJul 26, 2021