CVE-2018-7474: Textpattern

Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.

An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.

Affected products

Published 2018-03-14. Last modified 2026-06-17.