Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Typecho

First CVE: Oct 30, 2017Active for: 9 yearsTotal CVEs: 18
32.2
VTI Score
Medium

Typecho is a lightweight, open-source blogging platform that, despite a narrow product footprint, ranks among the more prominent targets in vulnerability disclosures, likely reflecting its popularity in certain deployment communities. Its vulnerabilities skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on authentication bypass, cross-site scripting, and information-disclosure flaws that are characteristic of web application platforms handling user input and session management. Defenders deploying or maintaining this platform should prioritize patching cycles and restrict administrative access; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
3.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Typecho over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 30, 2017
8 years ago
Most Recent CVE
Apr 7, 2025
473 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-35540CRITICAL
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Aug 20, 20249.035NOYES
CVE-2018-18753CRITICAL
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
Oct 29, 20189.831NONO
CVE-2023-24114CRITICAL
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
Feb 22, 20239.829NONO
CVE-2024-35539MEDIUM
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spa
Aug 19, 20246.528NOYES
CVE-2023-36299HIGH
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.
Aug 3, 20238.823NONO
CVE-2020-21038MEDIUM
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
May 8, 20236.121NONO
CVE-2023-49967HIGH
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
Dec 7, 20237.520NONO
CVE-2024-57369MEDIUM
Clickjacking vulnerability in typecho v1.2.1.
Jan 17, 20256.419NONO
CVE-2023-27130MEDIUM
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter.
Mar 16, 20234.819NONO
CVE-2017-16230MEDIUM
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/a
Oct 30, 20175.419NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
67%
11%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (44.4%)
Unknown0 (0.0%)
Required10 (55.6%)
Privileges Required
Low5 (27.8%)
High6 (33.3%)
None7 (38.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Typecho.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Typecho — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Typecho's Products

View all 2 CNAs →

Top CWEs