Skip to content
Noroxi

typesettercms records

14 published records for vendor typesettercms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • CVE-2018-6889
    37Monitor

    An issue was discovered in Typesetter 5.1.

    HighCVSS 8.8Proof of conceptEPSS 7%

    typesettercms · typesetterFeb 11, 2018

  • TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

    HighCVSS 8.8No exploitEPSS 1%

    typesettercms · typesetterMar 25, 2022

  • Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.

    HighCVSS 7.2Proof of conceptEPSS 16%

    typesettercms · typesetterSep 19, 2020

  • CVE-2018-6888
    33Monitor

    An issue was discovered in Typesetter 5.1.

    HighCVSS 8.0Proof of conceptEPSS 2%

    typesettercms · typesetterFeb 11, 2018

  • Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

    MediumCVSS 6.1No exploitEPSS 1%

    typesettercms · typesetterJun 21, 2021

  • Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.

    MediumCVSS 5.4No exploitEPSS 1%

    typesettercms · typesetterMay 13, 2019

  • include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.

    MediumCVSS 4.8No exploitEPSS 1%

    typesettercms · typesetterMay 9, 2019

  • Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.

    MediumCVSS 4.8No exploitEPSS 1%

    typesettercms · typesetterDec 11, 2020

  • index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.

    MediumCVSS 4.8No exploitEPSS 1%

    typesettercms · typesetterMay 13, 2019

  • index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.

    MediumCVSS 4.8No exploitEPSS 1%

    typesettercms · typesetterMay 13, 2019

  • Typesetter CMS Reflected XSS via Editing.php

    MediumCVSS 4.8No exploitEPSS 0%

    typesettercms · typesetterJan 14, 2026

  • Typesetter CMS Reflected XSS via Status.php

    MediumCVSS 4.8No exploitEPSS 0%

    typesettercms · typesetterJan 14, 2026

  • Typesetter CMS Reflected XSS via Move Message Handling

    MediumCVSS 4.8No exploitEPSS 0%

    typesettercms · typesetterJan 14, 2026

  • The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.

    MediumCVSS 4.3No exploitEPSS 0%

    typesettercms · typesetterJan 5, 2020