Known Vulnerabilities for products from Typecho
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Typecho".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-7025 json | Not Provided | 2026-04-26 | 2026-04-27 | |
| CVE-2023-36299 json | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-... | 8.8 - HIGH | 2023-08-03 | 2023-08-07 |
| CVE-2023-30184 json | A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML... | 5.4 - MEDIUM | 2023-05-04 | 2023-05-10 |
| CVE-2023-27711 json | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Commen... | 4.8 - MEDIUM | 2023-03-16 | 2023-03-22 |
| CVE-2023-27131 json | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Ed... | 4.8 - MEDIUM | 2023-03-16 | 2023-03-22 |
| CVE-2023-27130 json | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitra... | 4.8 - MEDIUM | 2023-03-16 | 2023-03-22 |
| CVE-2023-24114 json | typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. | 9.8 - CRITICAL | 2023-02-22 | 2023-03-03 |
| CVE-2020-21038 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-05-08 | 2023-05-11 |
| CVE-2018-18753 json | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. | 9.8 - CRITICAL | 2018-10-29 | 2019-01-28 |
| CVE-2017-16230 json | In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload i... | Not Provided | 2017-10-30 | 2025-04-20 |
Known software with vulnerabilities from Typecho
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Typecho | Typecho | 1.1 |