CVE-2021-28002
- EPSS 0.23%
- Veröffentlicht 19.08.2021 14:39:31
- Zuletzt bearbeitet 21.11.2024 05:58:58
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered ...
CVE-2021-28001
- EPSS 0.34%
- Veröffentlicht 19.08.2021 14:39:31
- Zuletzt bearbeitet 21.11.2024 05:58:58
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users v...
CVE-2020-23239
- EPSS 0.3%
- Veröffentlicht 26.07.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:39
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
CVE-2020-19510
- EPSS 0.43%
- Veröffentlicht 21.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:13
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
CVE-2021-30209
- EPSS 0.15%
- Veröffentlicht 15.04.2021 14:15:17
- Zuletzt bearbeitet 21.11.2024 06:03:31
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.
CVE-2020-35854
- EPSS 0.3%
- Veröffentlicht 26.01.2021 18:15:55
- Zuletzt bearbeitet 21.11.2024 05:28:19
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
CVE-2020-29458
- EPSS 0.18%
- Veröffentlicht 02.12.2020 09:15:11
- Zuletzt bearbeitet 21.11.2024 05:24:02
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
CVE-2015-8033
- EPSS 0.2%
- Veröffentlicht 14.08.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 02:37:53
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
CVE-2015-8032
- EPSS 0.2%
- Veröffentlicht 14.08.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 02:37:53
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
CVE-2018-7474
- EPSS 17.14%
- Veröffentlicht 14.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:12
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.