Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Textpattern

First CVE: Oct 31, 2006Active for: 20 yearsTotal CVEs: 30
36.9
VTI Score
Medium

Textpattern is a lightweight, open-source content management system whose vulnerability footprint, though narrowly focused on a single product, sits among more prominent platforms in the landscape due to its deployment across many small-to-medium publishing and blogging sites. Vulnerabilities affecting the platform reach meaningful severity levels and frequently acquire public exploit code, reflecting the accessibility and attractiveness of web-based content management systems to both researchers and attackers. The exposure recurs through input-handling and access-control weaknesses including cross-site scripting, unrestricted file uploads, cross-site request forgery, improper access control, and information disclosure—patterns typical of web application codebases where user input flows directly into template rendering and administrative interfaces. Defenders managing Textpattern deployments should prioritize updates promptly and restrict administrative access; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Textpattern over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2006
19 years ago
Most Recent CVE
Apr 21, 2026
97 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7474CRITICAL
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
Mar 14, 20189.844NOYES
CVE-2010-3205HIGH
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.
Sep 3, 20107.532NOYES
CVE-2020-19510CRITICAL
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
Jun 21, 20219.831NONO
CVE-2006-5615HIGH
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the
Oct 31, 20067.528NOYES
CVE-2021-44082HIGH
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by
Mar 29, 20228.327NONO
CVE-2023-24269HIGH
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
Apr 28, 20238.826NONO
CVE-2023-50038HIGH
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
Dec 28, 20238.825NONO
CVE-2023-26852HIGH
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.
Apr 12, 20237.224NONO
CVE-2011-5019MEDIUM
Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web sc
Jan 5, 20124.324NOYES
CVE-2026-30452MEDIUM
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned b
Apr 21, 20266.522NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
60%
30%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (70.0%)
Unknown9 (30.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (66.7%)
High1 (3.3%)
Unknown9 (30.0%)
User Interaction
None11 (36.7%)
Unknown9 (30.0%)
Required10 (33.3%)
Privileges Required
Low7 (23.3%)
High5 (16.7%)
None9 (30.0%)
Unknown9 (30.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
13.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Textpattern.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Textpattern — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Textpattern's Products

View all 2 CNAs →

Top CWEs