textpattern kayıtları
textpattern üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2018-7474Kavram kanıtı | An issue was discovered in Textpattern CMS 4.6.2 and earlier.textpattern · textpattern · CWE-89 | Kritik9,8 | — | %6,2 | 14 Mar 2018 |
39İzleyin | CVE-2020-19510İstismar yok | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.textpattern · textpattern · CWE-434 | Kritik9,8 | — | %1,5 | 21 Haz 2021 |
35İzleyin | CVE-2023-24269İstismar yok | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a textpattern · textpattern · CWE-434 | Yüksek8,8 | — | %1,1 | 28 Nis 2023 |
35İzleyin | CVE-2023-50038İstismar yok | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.textpattern · textpattern · CWE-434 | Yüksek8,8 | — | %0,8 | 28 Ara 2023 |
35İzleyin | CVE-2020-29458İstismar yok | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.textpattern · textpattern · CWE-352 | Yüksek8,8 | — | %0,7 | 2 Ara 2020 |
34İzleyin | CVE-2021-44082İstismar yok | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.textpattern · textpattern · CWE-79 | Yüksek8,3 | — | %3,0 | 29 Mar 2022 |
31İzleyin | CVE-2010-3205Kavram kanıtı | PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URtextpattern · textpattern · CWE-94 | Yüksek7,5 | — | %2,9 | 3 Eyl 2010 |
31İzleyin | CVE-2006-5615Kavram kanıtı | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exetextpattern · textpattern | Yüksek7,5 | — | %2,6 | 30 Eki 2006 |
30İzleyin | CVE-2018-1000090İstismar yok | textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in contetextpattern · textpattern · CWE-611 | Yüksek7,5 | — | %1,3 | 13 Mar 2018 |
29İzleyin | CVE-2023-36220İstismar yok | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain accesstextpattern · textpattern · CWE-22 | Yüksek7,2 | — | %3,4 | 7 Ağu 2023 |
29İzleyin | CVE-2023-26852Kavram kanıtı | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uptextpattern · textpattern · CWE-434 | Yüksek7,2 | — | %2,0 | 12 Nis 2023 |
27İzleyin | CVE-2008-5670İstismar yok | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to chatextpattern · textpattern · CWE-255 | Orta6,8 | — | %1,2 | 18 Ara 2008 |
26İzleyin | CVE-2021-30209İstismar yok | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veritextpattern · textpattern · CWE-434 | Orta6,5 | — | %0,8 | 15 Nis 2021 |
26İzleyin | CVE-2026-30452İstismar yok | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with ltextpattern · textpattern · CWE-284 | Orta6,5 | — | %0,3 | 21 Nis 2026 |
21İzleyin | CVE-2021-28002İstismar yok | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacketextpattern · textpattern · CWE-79 | Orta5,4 | — | %1,1 | 19 Ağu 2021 |
21İzleyin | CVE-2021-28001İstismar yok | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exectextpattern · textpattern · CWE-79 | Orta5,4 | — | %1,0 | 19 Ağu 2021 |
21İzleyin | CVE-2015-8033İstismar yok | In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.textpattern · textpattern · CWE-521 | Orta5,3 | — | %0,8 | 14 Ağu 2020 |
21İzleyin | CVE-2015-8032İstismar yok | In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.textpattern · textpattern · CWE-269 | Orta5,3 | — | %0,8 | 14 Ağu 2020 |
20İzleyin | CVE-2008-5669İstismar yok | index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a longtextpattern · textpattern · CWE-20 | Orta5,0 | — | %1,5 | 18 Ara 2008 |
20İzleyin | CVE-2011-3807İstismar yok | Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatiotextpattern · textpattern · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
20İzleyin | CVE-2023-53911İstismar yok | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpttextpattern · textpattern · CWE-79 | Orta5,1 | — | %0,3 | 17 Ara 2025 |
20İzleyin | CVE-2026-32986İstismar yok | Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injectiontextpattern · textpattern · CWE-79 | Orta5,1 | — | %0,3 | 20 Mar 2026 |
19İzleyin | CVE-2021-40658İstismar yok | Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.textpattern · textpattern · CWE-79 | Orta4,8 | — | %0,6 | 14 Haz 2022 |
19İzleyin | CVE-2020-35854İstismar yok | Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.textpattern · textpattern · CWE-79 | Orta4,8 | — | %0,6 | 26 Oca 2021 |
19İzleyin | CVE-2020-23239İstismar yok | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.textpattern · textpattern · CWE-79 | Orta4,8 | — | %0,5 | 26 Tem 2021 |
- CVE-2018-747441Planlayın
An issue was discovered in Textpattern CMS 4.6.2 and earlier.
KritikCVSS 9,8Kavram kanıtıEPSS %6textpattern · textpattern14 Mar 2018
- CVE-2020-1951039İzleyin
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
KritikCVSS 9,8İstismar yokEPSS %1textpattern · textpattern21 Haz 2021
- CVE-2023-2426935İzleyin
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a
YüksekCVSS 8,8İstismar yokEPSS %1textpattern · textpattern28 Nis 2023
- CVE-2023-5003835İzleyin
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
YüksekCVSS 8,8İstismar yokEPSS %1textpattern · textpattern28 Ara 2023
- CVE-2020-2945835İzleyin
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
YüksekCVSS 8,8İstismar yokEPSS %1textpattern · textpattern2 Ara 2020
- CVE-2021-4408234İzleyin
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.
YüksekCVSS 8,3İstismar yokEPSS %3textpattern · textpattern29 Mar 2022
- CVE-2010-320531İzleyin
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR
YüksekCVSS 7,5Kavram kanıtıEPSS %3textpattern · textpattern3 Eyl 2010
- CVE-2006-561531İzleyin
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe
YüksekCVSS 7,5Kavram kanıtıEPSS %3textpattern · textpattern30 Eki 2006
- CVE-2018-100009030İzleyin
textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte
YüksekCVSS 7,5İstismar yokEPSS %1textpattern · textpattern13 Mar 2018
- CVE-2023-3622029İzleyin
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access
YüksekCVSS 7,2İstismar yokEPSS %3textpattern · textpattern7 Ağu 2023
- CVE-2023-2685229İzleyin
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up
YüksekCVSS 7,2Kavram kanıtıEPSS %2textpattern · textpattern12 Nis 2023
- CVE-2008-567027İzleyin
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha
OrtaCVSS 6,8İstismar yokEPSS %1textpattern · textpattern18 Ara 2008
- CVE-2021-3020926İzleyin
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri
OrtaCVSS 6,5İstismar yokEPSS %1textpattern · textpattern15 Nis 2021
- CVE-2026-3045226İzleyin
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l
OrtaCVSS 6,5İstismar yokEPSS %0textpattern · textpattern21 Nis 2026
- CVE-2021-2800221İzleyin
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke
OrtaCVSS 5,4İstismar yokEPSS %1textpattern · textpattern19 Ağu 2021
- CVE-2021-2800121İzleyin
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec
OrtaCVSS 5,4İstismar yokEPSS %1textpattern · textpattern19 Ağu 2021
- CVE-2015-803321İzleyin
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
OrtaCVSS 5,3İstismar yokEPSS %1textpattern · textpattern14 Ağu 2020
- CVE-2015-803221İzleyin
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
OrtaCVSS 5,3İstismar yokEPSS %1textpattern · textpattern14 Ağu 2020
- CVE-2008-566920İzleyin
index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long
OrtaCVSS 5,0İstismar yokEPSS %2textpattern · textpattern18 Ara 2008
- CVE-2011-380720İzleyin
Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio
OrtaCVSS 5,0İstismar yokEPSS %1textpattern · textpattern23 Eyl 2011
- CVE-2023-5391120İzleyin
Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt
OrtaCVSS 5,1İstismar yokEPSS %0textpattern · textpattern17 Ara 2025
- CVE-2026-3298620İzleyin
Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
OrtaCVSS 5,1İstismar yokEPSS %0textpattern · textpattern20 Mar 2026
- CVE-2021-4065819İzleyin
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
OrtaCVSS 4,8İstismar yokEPSS %1textpattern · textpattern14 Haz 2022
- CVE-2020-3585419İzleyin
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
OrtaCVSS 4,8İstismar yokEPSS %1textpattern · textpattern26 Oca 2021
- CVE-2020-2323919İzleyin
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
OrtaCVSS 4,8İstismar yokEPSS %1textpattern · textpattern26 Tem 2021