Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Textpattern MEDIUM 6.5
CVE-2026-30452

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privil…

Mitigation only
Fix from $1,600 2026-04-21
Textpattern MEDIUM 6.1
CVE-2026-32986

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploit…

No fix yet
Fix from $1,600 2026-03-20
Textpattern MEDIUM 5.4
CVE-2023-53911

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject mal…

No fix yet
Fix from $1,600 2025-12-17
Textpattern HIGH 8.8
CVE-2023-50038

There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

No fix yet
Fix from $1,950 2023-12-28
Textpattern HIGH 7.2
CVE-2023-36220

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensi…

No fix yet
Fix from $1,950 2023-08-07
Textpattern HIGH 8.8
CVE-2023-24269

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Z…

No fix yet
Fix from $1,950 2023-04-28
Textpattern HIGH 8.3
CVE-2021-44082

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to t…

No fix yet
Fix from $1,950 2022-03-29
Textpattern MEDIUM 5.4
CVE-2021-28001

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbit…

No fix yet
Fix from $1,600 2021-08-19
Textpattern MEDIUM 5.4
CVE-2021-28002

A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to exe…

No fix yet
Fix from $1,600 2021-08-19
Textpattern CRITICAL 9.8
CVE-2020-19510

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

No fix yet
Fix from $2,300 2021-06-21
Textpattern MEDIUM 6.5
CVE-2021-30209

Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification,…

No fix yet
Fix from $1,600 2021-04-15
Textpattern HIGH 8.8
CVE-2020-29458

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

No fix yet
Fix from $1,950 2020-12-02
Textpattern HIGH 7.5
CVE-2018-1000090

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the…

No fix yet
Fix from $1,950 2018-03-13
Textpattern MEDIUM 5.0
CVE-2011-3807

Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

Mitigation only
Fix from $1,600 2011-09-24
Textpattern HIGH 7.5
CVE-2010-3205

PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2010-09-03
Textpattern MEDIUM 6.8
CVE-2008-5670

Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a pas…

Mitigation only
Fix from $1,600 2008-12-19