High severity7.2NVD Advisory· Published Aug 7, 2023· Updated Jun 17, 2026
CVE-2023-36220
CVE-2023-36220
Description
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:textpattern:textpattern:4.8.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:textpattern:textpattern:4.8.8:*:*:*:*:*:*:*
- (no CPE)range: =4.8.8
- Textpattern/CMSdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/172967/Textpattern-CMS-4.8.8-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- release-demo.textpattern.convdProduct
- textpattern.comnvdProduct
- textpattern.com/file_download/118/textpattern-4.8.8.zipnvdRelease Notes
News mentions
0No linked articles in our index yet.