typesettercms records
14 published records for vendor typesettercms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2018-6889Proof of concept | An issue was discovered in Typesetter 5.1.typesettercms · typesetter · CWE-94 | High8.8 | — | 6.7% | Feb 11, 2018 |
35Monitor | CVE-2022-25523No exploit | TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.typesettercms · typesetter · CWE-352 | High8.8 | — | 0.6% | Mar 25, 2022 |
33Monitor | CVE-2020-25790Proof of concept | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.typesettercms · typesetter · CWE-434 | High7.2 | — | 15.6% | Sep 19, 2020 |
33Monitor | CVE-2018-6888Proof of concept | An issue was discovered in Typesetter 5.1.typesettercms · typesetter · CWE-352 | High8.0 | — | 1.9% | Feb 11, 2018 |
24Monitor | CVE-2020-19511No exploit | Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,typesettercms · typesetter · CWE-79 | Medium6.1 | — | 0.8% | Jun 21, 2021 |
21Monitor | CVE-2018-16639No exploit | Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.typesettercms · typesetter · CWE-79 | Medium5.4 | — | 0.7% | May 13, 2019 |
19Monitor | CVE-2018-20837No exploit | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.typesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.7% | May 9, 2019 |
19Monitor | CVE-2020-35126No exploit | Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.typesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.7% | Dec 11, 2020 |
19Monitor | CVE-2018-16625No exploit | index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.typesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.7% | May 13, 2019 |
19Monitor | CVE-2018-16626No exploit | index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.typesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.7% | May 13, 2019 |
19Monitor | CVE-2025-71164No exploit | Typesetter CMS Reflected XSS via Editing.phptypesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.2% | Jan 14, 2026 |
19Monitor | CVE-2025-71165No exploit | Typesetter CMS Reflected XSS via Status.phptypesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.2% | Jan 14, 2026 |
19Monitor | CVE-2025-71166No exploit | Typesetter CMS Reflected XSS via Move Message Handlingtypesettercms · typesetter · CWE-79 | Medium4.8 | — | 0.2% | Jan 14, 2026 |
17Monitor | CVE-2019-20077No exploit | The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.typesettercms · typesetter · CWE-352 | Medium4.3 | — | 0.4% | Jan 5, 2020 |
- CVE-2018-688937Monitor
An issue was discovered in Typesetter 5.1.
HighCVSS 8.8Proof of conceptEPSS 7%typesettercms · typesetterFeb 11, 2018
- CVE-2022-2552335Monitor
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
HighCVSS 8.8No exploitEPSS 1%typesettercms · typesetterMar 25, 2022
- CVE-2020-2579033Monitor
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.
HighCVSS 7.2Proof of conceptEPSS 16%typesettercms · typesetterSep 19, 2020
- CVE-2018-688833Monitor
An issue was discovered in Typesetter 5.1.
HighCVSS 8.0Proof of conceptEPSS 2%typesettercms · typesetterFeb 11, 2018
- CVE-2020-1951124Monitor
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
MediumCVSS 6.1No exploitEPSS 1%typesettercms · typesetterJun 21, 2021
- CVE-2018-1663921Monitor
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
MediumCVSS 5.4No exploitEPSS 1%typesettercms · typesetterMay 13, 2019
- CVE-2018-2083719Monitor
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
MediumCVSS 4.8No exploitEPSS 1%typesettercms · typesetterMay 9, 2019
- CVE-2020-3512619Monitor
Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.
MediumCVSS 4.8No exploitEPSS 1%typesettercms · typesetterDec 11, 2020
- CVE-2018-1662519Monitor
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
MediumCVSS 4.8No exploitEPSS 1%typesettercms · typesetterMay 13, 2019
- CVE-2018-1662619Monitor
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
MediumCVSS 4.8No exploitEPSS 1%typesettercms · typesetterMay 13, 2019
- CVE-2025-7116419Monitor
Typesetter CMS Reflected XSS via Editing.php
MediumCVSS 4.8No exploitEPSS 0%typesettercms · typesetterJan 14, 2026
- CVE-2025-7116519Monitor
Typesetter CMS Reflected XSS via Status.php
MediumCVSS 4.8No exploitEPSS 0%typesettercms · typesetterJan 14, 2026
- CVE-2025-7116619Monitor
Typesetter CMS Reflected XSS via Move Message Handling
MediumCVSS 4.8No exploitEPSS 0%typesettercms · typesetterJan 14, 2026
- CVE-2019-2007717Monitor
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.
MediumCVSS 4.3No exploitEPSS 0%typesettercms · typesetterJan 5, 2020