typecho 漏洞与 CVE 列表(18)

产品(CPE): — CVE 数: 18

typecho 漏洞概览

汇总 typecho 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

常见弱点模式包括 XXE、SSRF、开放重定向与路径处理缺陷,在 生产负载与软件部署 使用场景中可能带来 会话劫持与文件覆盖 等风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 11818 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2024-46494 A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article. [email protected] 5.4 0.58% 2025-04-07 2025-04-23
CVE-2024-57369 Clickjacking vulnerability in typecho v1.2.1. [email protected] 6.4 0.12% 2025-01-17 2025-04-23
CVE-2024-35540 A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. [email protected] 9.0 6.78% 2024-08-20 2024-08-21
CVE-2024-35539 Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently. [email protected] 6.5 3.39% 2024-08-19 2025-05-01
CVE-2024-35538 Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests. [email protected] 5.3 0.55% 2024-08-19 2025-04-28
CVE-2023-6615 A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some unknown functionality of the file /admin/manage-users.php. The manipulation of the argument page leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-247250 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 3.5 0.09% 2023-12-08 2024-11-21
CVE-2023-6614 A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this vulnerability is an unknown functionality of the file /admin/manage-pages.php of the component Page Handler. The manipulation leads to backdoor. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.7 0.03% 2023-12-08 2024-11-21
CVE-2023-6613 A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown function of the file /admin/options-theme.php of the component Logo Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247248. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.4 0.06% 2023-12-08 2024-11-21
CVE-2023-49967 Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc. [email protected] 7.5 0.31% 2023-12-07 2024-11-21
CVE-2023-36299 A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. [email protected] 8.8 11.90% 2023-08-03 2024-11-21
CVE-2020-21038 Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. [email protected] 6.1 0.20% 2023-05-08 2025-01-29
CVE-2023-30184 A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment. [email protected] 5.4 0.20% 2023-05-04 2025-01-29
CVE-2023-27711 Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component. [email protected] 4.8 0.38% 2023-03-16 2025-02-26
CVE-2023-27131 Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter. [email protected] 4.8 0.95% 2023-03-16 2025-02-26
CVE-2023-27130 Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter. [email protected] 4.8 0.36% 2023-03-16 2025-03-03
CVE-2023-24114 typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. [email protected] 9.8 2.73% 2023-02-22 2025-03-18
CVE-2018-18753 Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. [email protected] 9.8 2.46% 2018-10-29 2024-11-21
CVE-2017-16230 In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit. [email protected] 5.4 0.21% 2017-10-30 2026-05-13
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence