Записи Textpattern
30 опубликованных записей вендора textpattern.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2018-7474Proof of concept | An issue was discovered in Textpattern CMS 4.6.2 and earlier.textpattern · textpattern · CWE-89 | Критическая9,8 | — | 6,2 % | 14 мар. 2018 г. |
39Наблюдать | CVE-2020-19510Эксплойта нет | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.textpattern · textpattern · CWE-434 | Критическая9,8 | — | 1,5 % | 21 июн. 2021 г. |
35Наблюдать | CVE-2023-24269Эксплойта нет | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a textpattern · textpattern · CWE-434 | Высокая8,8 | — | 1,1 % | 28 апр. 2023 г. |
35Наблюдать | CVE-2023-50038Эксплойта нет | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.textpattern · textpattern · CWE-434 | Высокая8,8 | — | 0,8 % | 28 дек. 2023 г. |
35Наблюдать | CVE-2020-29458Эксплойта нет | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.textpattern · textpattern · CWE-352 | Высокая8,8 | — | 0,7 % | 2 дек. 2020 г. |
34Наблюдать | CVE-2021-44082Эксплойта нет | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.textpattern · textpattern · CWE-79 | Высокая8,3 | — | 3,0 % | 29 мар. 2022 г. |
31Наблюдать | CVE-2010-3205Proof of concept | PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URtextpattern · textpattern · CWE-94 | Высокая7,5 | — | 2,9 % | 3 сент. 2010 г. |
31Наблюдать | CVE-2006-5615Proof of concept | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exetextpattern · textpattern | Высокая7,5 | — | 2,6 % | 30 окт. 2006 г. |
30Наблюдать | CVE-2018-1000090Эксплойта нет | textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in contetextpattern · textpattern · CWE-611 | Высокая7,5 | — | 1,3 % | 13 мар. 2018 г. |
29Наблюдать | CVE-2023-36220Эксплойта нет | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain accesstextpattern · textpattern · CWE-22 | Высокая7,2 | — | 3,4 % | 7 авг. 2023 г. |
29Наблюдать | CVE-2023-26852Proof of concept | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uptextpattern · textpattern · CWE-434 | Высокая7,2 | — | 2,0 % | 12 апр. 2023 г. |
27Наблюдать | CVE-2008-5670Эксплойта нет | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to chatextpattern · textpattern · CWE-255 | Средняя6,8 | — | 1,2 % | 18 дек. 2008 г. |
26Наблюдать | CVE-2021-30209Эксплойта нет | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veritextpattern · textpattern · CWE-434 | Средняя6,5 | — | 0,8 % | 15 апр. 2021 г. |
26Наблюдать | CVE-2026-30452Эксплойта нет | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with ltextpattern · textpattern · CWE-284 | Средняя6,5 | — | 0,3 % | 21 апр. 2026 г. |
21Наблюдать | CVE-2021-28002Эксплойта нет | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacketextpattern · textpattern · CWE-79 | Средняя5,4 | — | 1,1 % | 19 авг. 2021 г. |
21Наблюдать | CVE-2021-28001Эксплойта нет | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exectextpattern · textpattern · CWE-79 | Средняя5,4 | — | 1,0 % | 19 авг. 2021 г. |
21Наблюдать | CVE-2015-8033Эксплойта нет | In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.textpattern · textpattern · CWE-521 | Средняя5,3 | — | 0,8 % | 14 авг. 2020 г. |
21Наблюдать | CVE-2015-8032Эксплойта нет | In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.textpattern · textpattern · CWE-269 | Средняя5,3 | — | 0,8 % | 14 авг. 2020 г. |
20Наблюдать | CVE-2008-5669Эксплойта нет | index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a longtextpattern · textpattern · CWE-20 | Средняя5,0 | — | 1,5 % | 18 дек. 2008 г. |
20Наблюдать | CVE-2011-3807Эксплойта нет | Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatiotextpattern · textpattern · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
20Наблюдать | CVE-2023-53911Эксплойта нет | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpttextpattern · textpattern · CWE-79 | Средняя5,1 | — | 0,3 % | 17 дек. 2025 г. |
20Наблюдать | CVE-2026-32986Эксплойта нет | Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injectiontextpattern · textpattern · CWE-79 | Средняя5,1 | — | 0,3 % | 20 мар. 2026 г. |
19Наблюдать | CVE-2021-40658Эксплойта нет | Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.textpattern · textpattern · CWE-79 | Средняя4,8 | — | 0,6 % | 14 июн. 2022 г. |
19Наблюдать | CVE-2020-35854Эксплойта нет | Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.textpattern · textpattern · CWE-79 | Средняя4,8 | — | 0,6 % | 26 янв. 2021 г. |
19Наблюдать | CVE-2020-23239Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.textpattern · textpattern · CWE-79 | Средняя4,8 | — | 0,5 % | 26 июл. 2021 г. |
- CVE-2018-747441В плане
An issue was discovered in Textpattern CMS 4.6.2 and earlier.
КритическаяCVSS 9,8Proof of conceptEPSS 6 %textpattern · textpattern14 мар. 2018 г.
- CVE-2020-1951039Наблюдать
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %textpattern · textpattern21 июн. 2021 г.
- CVE-2023-2426935Наблюдать
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %textpattern · textpattern28 апр. 2023 г.
- CVE-2023-5003835Наблюдать
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %textpattern · textpattern28 дек. 2023 г.
- CVE-2020-2945835Наблюдать
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %textpattern · textpattern2 дек. 2020 г.
- CVE-2021-4408234Наблюдать
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.
ВысокаяCVSS 8,3Эксплойта нетEPSS 3 %textpattern · textpattern29 мар. 2022 г.
- CVE-2010-320531Наблюдать
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %textpattern · textpattern3 сент. 2010 г.
- CVE-2006-561531Наблюдать
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %textpattern · textpattern30 окт. 2006 г.
- CVE-2018-100009030Наблюдать
textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %textpattern · textpattern13 мар. 2018 г.
- CVE-2023-3622029Наблюдать
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %textpattern · textpattern7 авг. 2023 г.
- CVE-2023-2685229Наблюдать
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up
ВысокаяCVSS 7,2Proof of conceptEPSS 2 %textpattern · textpattern12 апр. 2023 г.
- CVE-2008-567027Наблюдать
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha
СредняяCVSS 6,8Эксплойта нетEPSS 1 %textpattern · textpattern18 дек. 2008 г.
- CVE-2021-3020926Наблюдать
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri
СредняяCVSS 6,5Эксплойта нетEPSS 1 %textpattern · textpattern15 апр. 2021 г.
- CVE-2026-3045226Наблюдать
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l
СредняяCVSS 6,5Эксплойта нетEPSS 0 %textpattern · textpattern21 апр. 2026 г.
- CVE-2021-2800221Наблюдать
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke
СредняяCVSS 5,4Эксплойта нетEPSS 1 %textpattern · textpattern19 авг. 2021 г.
- CVE-2021-2800121Наблюдать
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec
СредняяCVSS 5,4Эксплойта нетEPSS 1 %textpattern · textpattern19 авг. 2021 г.
- CVE-2015-803321Наблюдать
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %textpattern · textpattern14 авг. 2020 г.
- CVE-2015-803221Наблюдать
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %textpattern · textpattern14 авг. 2020 г.
- CVE-2008-566920Наблюдать
index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long
СредняяCVSS 5,0Эксплойта нетEPSS 2 %textpattern · textpattern18 дек. 2008 г.
- CVE-2011-380720Наблюдать
Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio
СредняяCVSS 5,0Эксплойта нетEPSS 1 %textpattern · textpattern23 сент. 2011 г.
- CVE-2023-5391120Наблюдать
Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt
СредняяCVSS 5,1Эксплойта нетEPSS 0 %textpattern · textpattern17 дек. 2025 г.
- CVE-2026-3298620Наблюдать
Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
СредняяCVSS 5,1Эксплойта нетEPSS 0 %textpattern · textpattern20 мар. 2026 г.
- CVE-2021-4065819Наблюдать
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %textpattern · textpattern14 июн. 2022 г.
- CVE-2020-3585419Наблюдать
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %textpattern · textpattern26 янв. 2021 г.
- CVE-2020-2323919Наблюдать
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %textpattern · textpattern26 июл. 2021 г.