CVE-2018-7474: Textpattern
Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
Affected products
- Textpattern Textpattern: up to and including 4.6.2
Published 2018-03-14. Last modified 2026-06-17.