CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2021-47976 HIGH

TextPattern CMS 4.9.0-dev Authenticated Remote Code Execution via Plugin Upload

CVSS 8.7 EPSS 0.32% May 16, 2026
CVE-2021-47943 HIGH

TextPattern CMS 4.8.7 Remote Code Execution via File Upload

CVSS 8.7 EPSS 0.62% May 10, 2026
CVE-2026-30452 MEDIUM

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to mo…

CVSS 6.5 EPSS 0.35% Apr 21, 2026
CVE-2026-5344 MEDIUM

Textpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal

CVSS 5.3 EPSS 0.40% Apr 2, 2026
CVE-2026-32986 MEDIUM

Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

CVSS 5.1 EPSS 0.26% Mar 20, 2026
CVE-2023-53911 MEDIUM

Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

CVSS 5.1 EPSS 0.31% Dec 17, 2025
CVE-2023-50038 HIGH

There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

CVSS 8.8 EPSS 0.81% Dec 28, 2023
CVE-2023-36220 HIGH

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive infor…

CVSS 7.2 EPSS 3.39% Aug 7, 2023
CVE-2023-24269 HIGH

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVSS 8.8 EPSS 1.11% Apr 28, 2023
CVE-2023-26852 HIGH

An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted P…

CVSS 7.2 EPSS 1.99% Apr 12, 2023
CVE-2021-40642 MEDIUM

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php.…

CVSS 4.3 EPSS 0.52% Jun 29, 2022
CVE-2021-40658 MEDIUM

Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

CVSS 4.8 EPSS 0.58% Jun 14, 2022
CVE-2021-44082 HIGH

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger rem…

CVSS 8.3 EPSS 3.04% Mar 29, 2022
CVE-2021-28002 MEDIUM

A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbit…

CVSS 5.4 EPSS 1.07% Aug 19, 2021
CVE-2021-28001 MEDIUM

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code…

CVSS 5.4 EPSS 1.02% Aug 19, 2021
CVE-2020-23239 MEDIUM

Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

CVSS 4.8 EPSS 0.51% Jul 26, 2021
CVE-2020-19510 CRITICAL

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

CVSS 9.8 EPSS 1.46% Jun 21, 2021
CVE-2021-30209 MEDIUM

Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may…

CVSS 6.5 EPSS 0.76% Apr 15, 2021
CVE-2020-35854 MEDIUM

Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

CVSS 4.8 EPSS 0.57% Jan 25, 2021
CVE-2020-29458 HIGH

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

CVSS 8.8 EPSS 0.66% Dec 2, 2020
CVE-2015-8033 MEDIUM

In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

CVSS 5.3 EPSS 0.81% Aug 14, 2020
CVE-2015-8032 MEDIUM

In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

CVSS 5.3 EPSS 0.81% Aug 14, 2020
CVE-2018-7474 CRITICAL

An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.

CVSS 9.8 EPSS 6.24% Mar 14, 2018
CVE-2018-1000090 HIGH

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web serve…

CVSS 7.5 EPSS 1.34% Mar 13, 2018
CVE-2014-4737 MEDIUM

Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to se…

CVSS 4.3 EPSS 1.93% Oct 10, 2014

Showing 1 to 25 CVEs · page 1 (more available)