Vulnerabilities (CVE)

Filtered by vendor Typecho Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49967 1 Typecho 1 Typecho 2023-12-09 N/A 7.5 HIGH
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
CVE-2023-36299 1 Typecho 1 Typecho 2023-08-07 N/A 8.8 HIGH
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.