Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Typesettercms

First CVE: Feb 12, 2018Active for: 8 yearsTotal CVEs: 14
37.4
VTI Score
Medium

Typesettercms maintains a focused content management system product that sits in the web-application tier and has attracted public exploit tooling, drawing interest from developers and security researchers. The vulnerability exposure recurs through application-layer weakness classes centered on input handling and code generation—cross-site scripting, cross-site request forgery, code injection, and unrestricted file uploads—which are characteristic of web-facing CMS platforms and reflect the intersection of user-controlled content and dynamic page rendering. Current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Typesettercms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2018
8 years ago
Most Recent CVE
Jan 14, 2026
191 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25790HIGH
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this repor
Sep 19, 20207.243NOYES
CVE-2018-6889HIGH
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced p
Feb 12, 20188.841NOYES
CVE-2018-6888HIGH
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a mali
Feb 12, 20188.035NOYES
CVE-2022-25523HIGH
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
Mar 25, 20228.829NONO
CVE-2025-71164MEDIUM
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] i
Jan 14, 20265.425NONO
CVE-2025-71165MEDIUM
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality.
Jan 14, 20265.422NONO
CVE-2025-71166MEDIUM
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message ha
Jan 14, 20265.421NONO
CVE-2020-19511MEDIUM
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
Jun 21, 20216.121NONO
CVE-2018-16639MEDIUM
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
May 13, 20195.421NONO
CVE-2018-16625MEDIUM
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
May 13, 20194.819NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
71%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (14.3%)
Unknown0 (0.0%)
Required12 (85.7%)
Privileges Required
Low6 (42.9%)
High5 (35.7%)
None3 (21.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Typesettercms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Typesettercms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Typesettercms's Products

View all 2 CNAs →

Top CWEs