textpattern
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting textpattern.
- CVE-2021-47976TextPattern CMS 4.9.0-dev Authenticated Remote Code Execution via Plugin Upload8.8
- CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File Upload8.8
- CVE-2026-30452Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with high...6.5
- CVE-2026-32986Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection6.1
- CVE-2023-53911Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt5.4
- CVE-2023-50038There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.8.8
- CVE-2023-36220Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.7.2
- CVE-2023-24269An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.8.8
- CVE-2023-26852An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.7.2
- CVE-2021-40642Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_lo...4.3
- CVE-2021-40658Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.4.8
- CVE-2021-44082textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webs...8.3
- CVE-2021-28002A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entere...5.4
- CVE-2021-28001A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the...5.4
- CVE-2020-23239Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.4.8