TextpatternCVEs & Vulnerabilities

30 CVEs affecting Textpattern products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

textpattern 40
CVE-2026-30452MEDIUM

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in textpattern/include/txp_article.php, an attacker can bypass authorization checks and overwrite content belonging to other users.

21 Apr 2026
6.5
CVSS
CVE-2026-32986MEDIUM

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods.

20 Mar 2026
6.1
CVSS
CVE-2023-53911MEDIUM

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

18 Dec 2025
5.4
CVSS
CVE-2023-50038HIGH

There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

28 Dec 2023
8.8
CVSS
CVE-2023-36220HIGH

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.

7 Aug 2023
7.2
CVSS
CVE-2023-24269HIGH

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

29 Apr 2023
8.8
CVSS
CVE-2023-26852HIGH

An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.

12 Apr 2023
7.2
CVSS
CVE-2021-40642MEDIUM

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

29 Jun 2022
4.3
CVSS
CVE-2021-40658MEDIUM

Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

14 Jun 2022
4.8
CVSS
CVE-2021-44082HIGH

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

30 Mar 2022
8.3
CVSS
CVE-2021-28002MEDIUM

A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page.

19 Aug 2021
5.4
CVSS
CVE-2021-28001MEDIUM

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.

19 Aug 2021
5.4
CVSS
CVE-2020-23239MEDIUM

Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

26 Jul 2021
4.8
CVSS
CVE-2020-19510CRITICAL

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

21 Jun 2021
9.8
CVSS
CVE-2021-30209MEDIUM

Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.

15 Apr 2021
6.5
CVSS
CVE-2020-35854MEDIUM

Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

26 Jan 2021
4.8
CVSS
CVE-2020-29458HIGH

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

2 Dec 2020
8.8
CVSS
CVE-2015-8033MEDIUM

In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

14 Aug 2020
5.3
CVSS
CVE-2015-8032MEDIUM

In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

14 Aug 2020
5.3
CVSS
CVE-2018-7474CRITICALpoc

An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.

14 Mar 2018
9.8
CVSS
CVE-2018-1000090HIGH

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.

13 Mar 2018
7.5
CVSS
CVE-2014-4737MEDIUM

Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to setup/index.php.

10 Oct 2014
4.3
CVSS
CVE-2011-5019MEDIUMpoc

Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

5 Jan 2012
4.3
CVSS
CVE-2011-3807MEDIUM

Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/txplib_db.php and certain other files.

24 Sep 2011
5.0
CVSS
CVE-2010-3205HIGHpoc

PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.

3 Sep 2010
7.5
CVSS
CVE-2008-5757LOW

Cross-site scripting (XSS) vulnerability in textarea/index.php in Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Body parameter in an article action. NOTE: some of these details are obtained from third party information.

30 Dec 2008
3.5
CVSS
CVE-2008-5670MEDIUM

Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.

19 Dec 2008
6.8
CVSS
CVE-2008-5669MEDIUM

index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter.

19 Dec 2008
5.0
CVSS
CVE-2008-5668MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.

19 Dec 2008
4.3
CVSS
CVE-2006-5615HIGHpoc

PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.

31 Oct 2006
7.5
CVSS
← PrevPage 1 / 1Next →