📦 Typecho

by Typecho

🔍 What is Typecho?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24114

CRITICAL CVSS 9.8 Feb 22, 2023

Typecho 1.1/17.10.30 contains a remote code execution vulnerability in install.php that allows attackers to execute arbitrary code on vulnerable servers. This affects all Typecho installations using t...

CVE-2023-49967

HIGH CVSS 7.5 Dec 7, 2023

Typecho v1.2.1 is vulnerable to an XML Quadratic Blowup attack through its XML-RPC endpoint at /index.php/action/xmlrpc. This allows attackers to cause denial of service by sending specially crafted X...

CVE-2023-36299

HIGH CVSS 8.8 Aug 3, 2023

This vulnerability allows remote attackers to upload malicious files and execute arbitrary code on Typecho v1.2.1 installations. Attackers can exploit the upload and options-general parameters in inde...

CVE-2024-46494

MEDIUM CVSS 5.4 Apr 7, 2025

This cross-site scripting vulnerability in Typecho v1.2.1 allows attackers to inject malicious scripts into the Name parameter when posting comments. When other users view the comment, the script exec...

CVE-2024-35538

MEDIUM CVSS 5.3 Aug 19, 2024

Typecho v1.3.0 contains a client IP spoofing vulnerability that allows attackers to falsify their IP addresses by manipulating X-Forwarded-For or Client-Ip HTTP headers. This affects all Typecho v1.3....