Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typesettercms typesetter 5.1 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2022-25523
TypesetterCMS v5.1 exists to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
Typesettercms Typesetter 5.1
8.8
CVSSv3
CVE-2018-6889
An issue exists in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
Typesettercms Typesetter 5.1
1 EDB exploit
8
CVSSv3
CVE-2018-6888
An issue exists in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an ant...
Typesettercms Typesetter 5.1
1 EDB exploit
7.2
CVSSv3
CVE-2020-25790
Typesetter CMS 5.x up to and including 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "con...
Typesettercms Typesetter
1 Github repository
6.1
CVSSv3
CVE-2020-19511
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
Typesettercms Typesetter 5.1
5.4
CVSSv3
CVE-2018-16639
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
Typesettercms Typesetter 5.1
4.8
CVSSv3
CVE-2020-35126
Typesetter CMS 5.x up to and including 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.
Typesettercms Typesetter
4.8
CVSSv3
CVE-2018-16625
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
Typesettercms Typesetter 5.1
4.8
CVSSv3
CVE-2018-16626
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
Typesettercms Typesetter 5.1
4.8
CVSSv3
CVE-2018-20837
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
Typesettercms Typesetter 5.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »