CVE-2017-16230: Typecho

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.

Affected products

  • Typecho Typecho: up to and including 1.1

Published 2017-10-30. Last modified 2026-06-17.