Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Typecho MEDIUM 5.4
CVE-2024-46494

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

No fix yet
Fix from $1,600 2025-04-07
Typecho MEDIUM 6.4
CVE-2024-57369

Clickjacking vulnerability in typecho v1.2.1.

No fix yet
Fix from $1,600 2025-01-17
Typecho CRITICAL 9.0
CVE-2024-35540

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Fix: after 1.2.1
Fix from $2,300 2024-08-20
Typecho MEDIUM 6.5
CVE-2024-35539

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post …

No fix yet
Fix from $1,600 2024-08-19
Typecho MEDIUM 5.3
CVE-2024-35538

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an ar…

No fix yet
Fix from $1,600 2024-08-19
Typecho MEDIUM 5.3
CVE-2023-6615

A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some unknown functionality of the fi…

No fix yet
Fix from $1,600 2023-12-08
Typecho HIGH 7.5
CVE-2023-49967

Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

No fix yet
Fix from $1,950 2023-12-07
Typecho HIGH 8.8
CVE-2023-36299

A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in in…

Patch available
Fix from $1,950 2023-08-03
Typecho MEDIUM 6.1
CVE-2020-21038

Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

No fix yet
Fix from $1,600 2023-05-08
Typecho MEDIUM 5.4
CVE-2023-30184

A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload i…

Fix: after 1.2.0
Fix from $1,600 2023-05-04
Typecho CRITICAL 9.8
CVE-2023-24114

typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

Fix: 1.2.0+
Fix from $2,300 2023-02-22
Typecho CRITICAL 9.8
CVE-2018-18753

Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

No fix yet
Fix from $2,300 2018-10-29
Typecho MEDIUM 5.4
CVE-2017-16230

In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, r…

Fix: after 1.1
Fix from $1,600 2017-10-30