CVE-2024-46494
- EPSS 0.03%
- Veröffentlicht 07.04.2025 00:00:00
- Zuletzt bearbeitet 23.04.2025 12:33:52
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.
CVE-2024-57369
- EPSS 0.12%
- Veröffentlicht 17.01.2025 20:15:29
- Zuletzt bearbeitet 23.04.2025 21:42:29
Clickjacking vulnerability in typecho v1.2.1.
- EPSS 4.96%
- Veröffentlicht 20.08.2024 15:15:21
- Zuletzt bearbeitet 21.08.2024 16:05:06
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-35539
- EPSS 3.01%
- Veröffentlicht 19.08.2024 21:15:09
- Zuletzt bearbeitet 01.05.2025 14:57:08
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.
CVE-2024-35538
- EPSS 0.72%
- Veröffentlicht 19.08.2024 21:15:09
- Zuletzt bearbeitet 28.04.2025 14:00:34
Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
CVE-2023-6615
- EPSS 0.09%
- Veröffentlicht 08.12.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:12
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some unknown functionality of the file /admin/manage-users.php. The manipulation of the argument page leads to information disclosure. Th...
CVE-2023-6614
- EPSS 0.03%
- Veröffentlicht 08.12.2023 16:15:20
- Zuletzt bearbeitet 21.11.2024 08:44:12
A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this vulnerability is an unknown functionality of the file /admin/manage-pages.php of the component Page Handler. The manipulation leads to backdoor. The attack can be ...
CVE-2023-6613
- EPSS 0.06%
- Veröffentlicht 08.12.2023 16:15:19
- Zuletzt bearbeitet 21.11.2024 08:44:12
A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown function of the file /admin/options-theme.php of the component Logo Handler. The manipulation leads to cross site scripting. It is possible to launch th...
CVE-2023-49967
- EPSS 0.31%
- Veröffentlicht 07.12.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:34:06
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
CVE-2023-36299
- EPSS 8.75%
- Veröffentlicht 03.08.2023 15:15:28
- Zuletzt bearbeitet 21.11.2024 08:09:30
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.