Typesetter

Vendor:

First CVE: Feb 12, 2018 · Active for 8 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Typesetter over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2018
8 years ago
Most Recent CVE
Jan 14, 2026
192 days ago

CVE Severity & Scoring

Typesetter14 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (14.3%)
Unknown0 (0.0%)
Required12 (85.7%)
Privileges Required
Low6 (42.9%)
High5 (35.7%)
None3 (21.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this repor
Sep 19, 20207.243NOYES
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced p
Feb 12, 20188.841NOYES
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a mali
Feb 12, 20188.035NOYES
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
Mar 25, 20228.829NONO
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] i
Jan 14, 20265.425NONO
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality.
Jan 14, 20265.422NONO
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message ha
Jan 14, 20265.421NONO
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
Jun 21, 20216.121NONO
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
May 13, 20195.421NONO
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
May 13, 20194.819NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Typesetter

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.196.21.5%02