İçeriğe atla
Noroxi

typesettercms kayıtları

typesettercms üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2018-6889
    37İzleyin

    An issue was discovered in Typesetter 5.1.

    YüksekCVSS 8,8Kavram kanıtıEPSS %7

    typesettercms · typesetter11 Şub 2018

  • CVE-2022-25523
    35İzleyin

    TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

    YüksekCVSS 8,8İstismar yokEPSS %1

    typesettercms · typesetter25 Mar 2022

  • CVE-2020-25790
    33İzleyin

    Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.

    YüksekCVSS 7,2Kavram kanıtıEPSS %16

    typesettercms · typesetter19 Eyl 2020

  • CVE-2018-6888
    33İzleyin

    An issue was discovered in Typesetter 5.1.

    YüksekCVSS 8,0Kavram kanıtıEPSS %2

    typesettercms · typesetter11 Şub 2018

  • CVE-2020-19511
    24İzleyin

    Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

    OrtaCVSS 6,1İstismar yokEPSS %1

    typesettercms · typesetter21 Haz 2021

  • CVE-2018-16639
    21İzleyin

    Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.

    OrtaCVSS 5,4İstismar yokEPSS %1

    typesettercms · typesetter13 May 2019

  • CVE-2018-20837
    19İzleyin

    include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.

    OrtaCVSS 4,8İstismar yokEPSS %1

    typesettercms · typesetter9 May 2019

  • CVE-2020-35126
    19İzleyin

    Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI.

    OrtaCVSS 4,8İstismar yokEPSS %1

    typesettercms · typesetter11 Ara 2020

  • CVE-2018-16625
    19İzleyin

    index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.

    OrtaCVSS 4,8İstismar yokEPSS %1

    typesettercms · typesetter13 May 2019

  • CVE-2018-16626
    19İzleyin

    index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.

    OrtaCVSS 4,8İstismar yokEPSS %1

    typesettercms · typesetter13 May 2019

  • CVE-2025-71164
    19İzleyin

    Typesetter CMS Reflected XSS via Editing.php

    OrtaCVSS 4,8İstismar yokEPSS %0

    typesettercms · typesetter14 Oca 2026

  • CVE-2025-71165
    19İzleyin

    Typesetter CMS Reflected XSS via Status.php

    OrtaCVSS 4,8İstismar yokEPSS %0

    typesettercms · typesetter14 Oca 2026

  • CVE-2025-71166
    19İzleyin

    Typesetter CMS Reflected XSS via Move Message Handling

    OrtaCVSS 4,8İstismar yokEPSS %0

    typesettercms · typesetter14 Oca 2026

  • CVE-2019-20077
    17İzleyin

    The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.

    OrtaCVSS 4,3İstismar yokEPSS %0

    typesettercms · typesetter5 Oca 2020