Textpattern / Textpattern
30 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-30452 | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to mo… | MEDIUM | 6.5 | Apr 21, 2026 |
| CVE-2026-5344 | Textpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal | MEDIUM | 5.3 | Apr 2, 2026 |
| CVE-2026-32986 | Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection | MEDIUM | 5.1 | Mar 20, 2026 |
| CVE-2023-53911 | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt | MEDIUM | 5.1 | Dec 17, 2025 |
| CVE-2023-50038 | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions. | HIGH | 8.8 | Dec 28, 2023 |
| CVE-2023-36220 | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive infor… | HIGH | 7.2 | Aug 7, 2023 |
| CVE-2023-24269 | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | HIGH | 8.8 | Apr 28, 2023 |
| CVE-2023-26852 | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted P… | HIGH | 7.2 | Apr 12, 2023 |
| CVE-2021-40642 | Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php.… | MEDIUM | 4.3 | Jun 29, 2022 |
| CVE-2021-40658 | Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”. | MEDIUM | 4.8 | Jun 14, 2022 |
| CVE-2021-44082 | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger rem… | HIGH | 8.3 | Mar 29, 2022 |
| CVE-2021-28002 | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbit… | MEDIUM | 5.4 | Aug 19, 2021 |
| CVE-2021-28001 | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code… | MEDIUM | 5.4 | Aug 19, 2021 |
| CVE-2020-23239 | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature. | MEDIUM | 4.8 | Jul 26, 2021 |
| CVE-2020-19510 | Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. | CRITICAL | 9.8 | Jun 21, 2021 |
| CVE-2021-30209 | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may… | MEDIUM | 6.5 | Apr 15, 2021 |
| CVE-2020-35854 | Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter. | MEDIUM | 4.8 | Jan 25, 2021 |
| CVE-2020-29458 | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. | HIGH | 8.8 | Dec 2, 2020 |
| CVE-2015-8033 | In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account. | MEDIUM | 5.3 | Aug 14, 2020 |
| CVE-2015-8032 | In Textpattern 4.5.7, an unprivileged author can change an article's markup setting. | MEDIUM | 5.3 | Aug 14, 2020 |
| CVE-2018-7474 | An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | CRITICAL | 9.8 | Mar 14, 2018 |
| CVE-2018-1000090 | textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web serve… | HIGH | 7.5 | Mar 13, 2018 |
| CVE-2014-4737 | Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to se… | MEDIUM | 4.3 | Oct 10, 2014 |
| CVE-2011-5019 | Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to in… | MEDIUM | 4.3 | Jan 5, 2012 |
| CVE-2011-3807 | Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error… | MEDIUM | 5.0 | Sep 24, 2011 |
Showing 1 to 25 of 30 CVEs