Typesettercms maintains a focused content management system product that sits in the web-application tier and has attracted public exploit tooling, drawing interest from developers and security researchers. The vulnerability exposure recurs through application-layer weakness classes centered on input handling and code generation—cross-site scripting, cross-site request forgery, code injection, and unrestricted file uploads—which are characteristic of web-facing CMS platforms and reflect the intersection of user-controlled content and dynamic page rendering. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typesettercms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25790HIGH Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this repor | Sep 19, 2020 | 7.2 | 43 | NO | YES |
CVE-2018-6889HIGH An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced p | Feb 12, 2018 | 8.8 | 41 | NO | YES |
CVE-2018-6888HIGH An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a mali | Feb 12, 2018 | 8.0 | 35 | NO | YES |
CVE-2022-25523HIGH TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request. | Mar 25, 2022 | 8.8 | 29 | NO | NO |
CVE-2025-71164MEDIUM Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] i | Jan 14, 2026 | 5.4 | 25 | NO | NO |
CVE-2025-71165MEDIUM Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. | Jan 14, 2026 | 5.4 | 22 | NO | NO |
CVE-2025-71166MEDIUM Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message ha | Jan 14, 2026 | 5.4 | 21 | NO | NO |
CVE-2020-19511MEDIUM Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes, | Jun 21, 2021 | 6.1 | 21 | NO | NO |
CVE-2018-16639MEDIUM Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | May 13, 2019 | 5.4 | 21 | NO | NO |
CVE-2018-16625MEDIUM index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | May 13, 2019 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typesettercms.
Media articles that mention a CVE ID that affects a product developed by Typesettercms — matched by CVE ID, not by vendor name.