Перейти к содержимому
Noroxi

Записи Textpattern

30 опубликованных записей вендора textpattern.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

30 записей
  • CVE-2018-7474
    41В плане

    An issue was discovered in Textpattern CMS 4.6.2 and earlier.

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    textpattern · textpattern14 мар. 2018 г.

  • CVE-2020-19510
    39Наблюдать

    Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    textpattern · textpattern21 июн. 2021 г.

  • CVE-2023-24269
    35Наблюдать

    An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    textpattern · textpattern28 апр. 2023 г.

  • CVE-2023-50038
    35Наблюдать

    There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    textpattern · textpattern28 дек. 2023 г.

  • CVE-2020-29458
    35Наблюдать

    Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    textpattern · textpattern2 дек. 2020 г.

  • CVE-2021-44082
    34Наблюдать

    textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.

    ВысокаяCVSS 8,3Эксплойта нетEPSS 3 %

    textpattern · textpattern29 мар. 2022 г.

  • CVE-2010-3205
    31Наблюдать

    PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    textpattern · textpattern3 сент. 2010 г.

  • CVE-2006-5615
    31Наблюдать

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    textpattern · textpattern30 окт. 2006 г.

  • CVE-2018-1000090
    30Наблюдать

    textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    textpattern · textpattern13 мар. 2018 г.

  • CVE-2023-36220
    29Наблюдать

    Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access

    ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %

    textpattern · textpattern7 авг. 2023 г.

  • CVE-2023-26852
    29Наблюдать

    An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up

    ВысокаяCVSS 7,2Proof of conceptEPSS 2 %

    textpattern · textpattern12 апр. 2023 г.

  • CVE-2008-5670
    27Наблюдать

    Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    textpattern · textpattern18 дек. 2008 г.

  • CVE-2021-30209
    26Наблюдать

    Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    textpattern · textpattern15 апр. 2021 г.

  • CVE-2026-30452
    26Наблюдать

    Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    textpattern · textpattern21 апр. 2026 г.

  • CVE-2021-28002
    21Наблюдать

    A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    textpattern · textpattern19 авг. 2021 г.

  • CVE-2021-28001
    21Наблюдать

    A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    textpattern · textpattern19 авг. 2021 г.

  • CVE-2015-8033
    21Наблюдать

    In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    textpattern · textpattern14 авг. 2020 г.

  • CVE-2015-8032
    21Наблюдать

    In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    textpattern · textpattern14 авг. 2020 г.

  • CVE-2008-5669
    20Наблюдать

    index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    textpattern · textpattern18 дек. 2008 г.

  • CVE-2011-3807
    20Наблюдать

    Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    textpattern · textpattern23 сент. 2011 г.

  • CVE-2023-53911
    20Наблюдать

    Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    textpattern · textpattern17 дек. 2025 г.

  • CVE-2026-32986
    20Наблюдать

    Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    textpattern · textpattern20 мар. 2026 г.

  • CVE-2021-40658
    19Наблюдать

    Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    textpattern · textpattern14 июн. 2022 г.

  • CVE-2020-35854
    19Наблюдать

    Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    textpattern · textpattern26 янв. 2021 г.

  • CVE-2020-23239
    19Наблюдать

    Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    textpattern · textpattern26 июл. 2021 г.