Typecho is a lightweight, open-source blogging platform that, despite a narrow product footprint, ranks among the more prominent targets in vulnerability disclosures, likely reflecting its popularity in certain deployment communities. Its vulnerabilities skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on authentication bypass, cross-site scripting, and information-disclosure flaws that are characteristic of web application platforms handling user input and session management. Defenders deploying or maintaining this platform should prioritize patching cycles and restrict administrative access; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typecho over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35540CRITICAL A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Aug 20, 2024 | 9.0 | 35 | NO | YES |
CVE-2018-18753CRITICAL Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-24114CRITICAL typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. | Feb 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-35539MEDIUM Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spa | Aug 19, 2024 | 6.5 | 28 | NO | YES |
CVE-2023-36299HIGH A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. | Aug 3, 2023 | 8.8 | 23 | NO | NO |
CVE-2020-21038MEDIUM Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-49967HIGH Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc. | Dec 7, 2023 | 7.5 | 20 | NO | NO |
CVE-2024-57369MEDIUM Clickjacking vulnerability in typecho v1.2.1. | Jan 17, 2025 | 6.4 | 19 | NO | NO |
CVE-2023-27130MEDIUM Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter. | Mar 16, 2023 | 4.8 | 19 | NO | NO |
CVE-2017-16230MEDIUM In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/a | Oct 30, 2017 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typecho.
Media articles that mention a CVE ID that affects a product developed by Typecho — matched by CVE ID, not by vendor name.