Vulnerabilities
Vulnerable Software
Typecho:  >> Typecho  Security Vulnerabilities
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
CVSS Score
6.1
EPSS Score
0.001
Published
2023-05-08
A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-05-04
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-03-16
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-03-16
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-03-16
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
CVSS Score
9.8
EPSS Score
0.014
Published
2023-02-22
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
CVSS Score
9.8
EPSS Score
0.026
Published
2018-10-29
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-10-30


Contact Us

Shodan ® - All rights reserved