Textpattern is a lightweight, open-source content management system whose vulnerability footprint, though narrowly focused on a single product, sits among more prominent platforms in the landscape due to its deployment across many small-to-medium publishing and blogging sites. Vulnerabilities affecting the platform reach meaningful severity levels and frequently acquire public exploit code, reflecting the accessibility and attractiveness of web-based content management systems to both researchers and attackers. The exposure recurs through input-handling and access-control weaknesses including cross-site scripting, unrestricted file uploads, cross-site request forgery, improper access control, and information disclosure—patterns typical of web application codebases where user input flows directly into template rendering and administrative interfaces. Defenders managing Textpattern deployments should prioritize updates promptly and restrict administrative access; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Textpattern over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7474CRITICAL An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | Mar 14, 2018 | 9.8 | 44 | NO | YES |
CVE-2010-3205HIGH PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter. | Sep 3, 2010 | 7.5 | 32 | NO | YES |
CVE-2020-19510CRITICAL Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. | Jun 21, 2021 | 9.8 | 31 | NO | NO |
CVE-2006-5615HIGH PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the | Oct 31, 2006 | 7.5 | 28 | NO | YES |
CVE-2021-44082HIGH textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by | Mar 29, 2022 | 8.3 | 27 | NO | NO |
CVE-2023-24269HIGH An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | Apr 28, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-50038HIGH There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions. | Dec 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-26852HIGH An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file. | Apr 12, 2023 | 7.2 | 24 | NO | NO |
CVE-2011-5019MEDIUM Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web sc | Jan 5, 2012 | 4.3 | 24 | NO | YES |
CVE-2026-30452MEDIUM Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned b | Apr 21, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Textpattern.
Media articles that mention a CVE ID that affects a product developed by Textpattern — matched by CVE ID, not by vendor name.