VYPR

CMS

by Textpattern

CVEs (5)

  • CVE-2021-47943HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content…

  • CVE-2020-29458HigDec 2, 2020
    risk 0.57cvss 8.8epss 0.01

    Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

  • CVE-2023-36220HigAug 7, 2023
    risk 0.47cvss 7.2epss 0.03

    Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.

  • CVE-2021-28002MedAug 19, 2021
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the…

  • CVE-2021-28001MedAug 19, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting…