Typosphere maintains a focused web application product (Typo) where vulnerability disclosures cluster around application-layer input-handling and data-access issues: cross-site scripting, SQL injection, and insufficiently random value generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typosphere over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4905HIGH Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack. | Nov 4, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-4904MEDIUM SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrar | Nov 4, 2008 | 6.0 | 17 | NO | NO |
CVE-2008-4903MEDIUM Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1 | Nov 4, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typosphere.
Media articles that mention a CVE ID that affects a product developed by Typosphere — matched by CVE ID, not by vendor name.