Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-30452 Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privil… Textpattern Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-32986 Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploit… Textpattern No fix yet Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2023-53911 Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject mal… Textpattern No fix yet Fix from $1,6002025-12-17 HIGH 8.8 CVE-2023-50038 There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions. Textpattern No fix yet Fix from $1,9502023-12-28 HIGH 7.2 CVE-2023-36220 Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensi… Textpattern No fix yet Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-24269 An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Z… Textpattern No fix yet Fix from $1,9502023-04-28 HIGH 7.2 CVE-2023-26852 An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a… Textpattern after 4.8.8 Fix from $1,9502023-04-12 HIGH 8.3 CVE-2021-44082 textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to t… Textpattern No fix yet Fix from $1,9502022-03-29 MEDIUM 5.4 CVE-2021-28001 A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbit… Textpattern No fix yet Fix from $1,6002021-08-19 MEDIUM 5.4 CVE-2021-28002 A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to exe… Textpattern No fix yet Fix from $1,6002021-08-19 CRITICAL 9.8 CVE-2020-19510 Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. Textpattern No fix yet Fix from $2,3002021-06-21 MEDIUM 6.5 CVE-2021-30209 Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification,… Textpattern No fix yet Fix from $1,6002021-04-15 HIGH 8.8 CVE-2020-29458 Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. Textpattern No fix yet Fix from $1,9502020-12-02 MEDIUM 5.3 CVE-2015-8033 In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account. Textpattern Patch available Fix from $1,6002020-08-14 MEDIUM 5.3 CVE-2015-8032 In Textpattern 4.5.7, an unprivileged author can change an article's markup setting. Textpattern Patch available Fix from $1,6002020-08-14 CRITICAL 9.8 CVE-2018-7474EPSS 6% An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. Textpattern after 4.6.2 Fix from $2,3002018-03-14 HIGH 7.5 CVE-2018-1000090 textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the… Textpattern No fix yet Fix from $1,9502018-03-13 MEDIUM 5.0 CVE-2011-3807 Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in… Textpattern Mitigation only Fix from $1,6002011-09-24 HIGH 7.5 CVE-2010-3205 PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the … Textpattern No fix yet Fix from $1,9502010-09-03 MEDIUM 6.8 CVE-2008-5670 Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a pas… Textpattern Mitigation only Fix from $1,6002008-12-19 MEDIUM 5.0 CVE-2008-5669 index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message … Textpattern Patch available Fix from $1,6002008-12-19 HIGH 7.5 CVE-2006-5615 PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbi… Textpattern Patch available Fix from $1,9502006-10-31