İçeriğe atla
Noroxi

textpattern kayıtları

textpattern üreticisine ait 30 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

30 kayıt
  • CVE-2018-7474
    41Planlayın

    An issue was discovered in Textpattern CMS 4.6.2 and earlier.

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    textpattern · textpattern14 Mar 2018

  • CVE-2020-19510
    39İzleyin

    Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    textpattern · textpattern21 Haz 2021

  • CVE-2023-24269
    35İzleyin

    An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a

    YüksekCVSS 8,8İstismar yokEPSS %1

    textpattern · textpattern28 Nis 2023

  • CVE-2023-50038
    35İzleyin

    There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

    YüksekCVSS 8,8İstismar yokEPSS %1

    textpattern · textpattern28 Ara 2023

  • CVE-2020-29458
    35İzleyin

    Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

    YüksekCVSS 8,8İstismar yokEPSS %1

    textpattern · textpattern2 Ara 2020

  • CVE-2021-44082
    34İzleyin

    textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body.

    YüksekCVSS 8,3İstismar yokEPSS %3

    textpattern · textpattern29 Mar 2022

  • CVE-2010-3205
    31İzleyin

    PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a UR

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    textpattern · textpattern3 Eyl 2010

  • CVE-2006-5615
    31İzleyin

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to exe

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    textpattern · textpattern30 Eki 2006

  • textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in conte

    YüksekCVSS 7,5İstismar yokEPSS %1

    textpattern · textpattern13 Mar 2018

  • CVE-2023-36220
    29İzleyin

    Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access

    YüksekCVSS 7,2İstismar yokEPSS %3

    textpattern · textpattern7 Ağu 2023

  • CVE-2023-26852
    29İzleyin

    An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by up

    YüksekCVSS 7,2Kavram kanıtıEPSS %2

    textpattern · textpattern12 Nis 2023

  • CVE-2008-5670
    27İzleyin

    Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to cha

    OrtaCVSS 6,8İstismar yokEPSS %1

    textpattern · textpattern18 Ara 2008

  • CVE-2021-30209
    26İzleyin

    Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security veri

    OrtaCVSS 6,5İstismar yokEPSS %1

    textpattern · textpattern15 Nis 2021

  • CVE-2026-30452
    26İzleyin

    Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with l

    OrtaCVSS 6,5İstismar yokEPSS %0

    textpattern · textpattern21 Nis 2026

  • CVE-2021-28002
    21İzleyin

    A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attacke

    OrtaCVSS 5,4İstismar yokEPSS %1

    textpattern · textpattern19 Ağu 2021

  • CVE-2021-28001
    21İzleyin

    A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to exec

    OrtaCVSS 5,4İstismar yokEPSS %1

    textpattern · textpattern19 Ağu 2021

  • CVE-2015-8033
    21İzleyin

    In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

    OrtaCVSS 5,3İstismar yokEPSS %1

    textpattern · textpattern14 Ağu 2020

  • CVE-2015-8032
    21İzleyin

    In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

    OrtaCVSS 5,3İstismar yokEPSS %1

    textpattern · textpattern14 Ağu 2020

  • CVE-2008-5669
    20İzleyin

    index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long

    OrtaCVSS 5,0İstismar yokEPSS %2

    textpattern · textpattern18 Ara 2008

  • CVE-2011-3807
    20İzleyin

    Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio

    OrtaCVSS 5,0İstismar yokEPSS %1

    textpattern · textpattern23 Eyl 2011

  • CVE-2023-53911
    20İzleyin

    Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

    OrtaCVSS 5,1İstismar yokEPSS %0

    textpattern · textpattern17 Ara 2025

  • CVE-2026-32986
    20İzleyin

    Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

    OrtaCVSS 5,1İstismar yokEPSS %0

    textpattern · textpattern20 Mar 2026

  • CVE-2021-40658
    19İzleyin

    Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

    OrtaCVSS 4,8İstismar yokEPSS %1

    textpattern · textpattern14 Haz 2022

  • CVE-2020-35854
    19İzleyin

    Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

    OrtaCVSS 4,8İstismar yokEPSS %1

    textpattern · textpattern26 Oca 2021

  • CVE-2020-23239
    19İzleyin

    Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

    OrtaCVSS 4,8İstismar yokEPSS %1

    textpattern · textpattern26 Tem 2021