publify_core
Core engine for the Publify blogging system, formerly known as Typo.
Activity
- Latest release
- 1y ago
- Total releases
- 24
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Nov 13, 2016
| Version | Released | |
|---|---|---|
10.0.3
patch
|
10.0.3
patch
Dependencies (47)
+ 39 more |
|
10.0.2
patch
|
10.0.2
patch
Dependencies (47)
+ 39 more |
|
10.0.1
patch
1 CVE
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev |
10.0.1
patch
Dependencies (46)
+ 38 more |
|
10.0.0
major
1 CVE
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev |
10.0.0
major
Dependencies (45)
+ 37 more |
|
9.2.10
patch
1 CVE
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev |
9.2.10
patch
Dependencies (40)
+ 32 more |
|
9.2.9
patch
5 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev |
9.2.9
patch
Dependencies (37)
+ 29 more |
|
9.2.8
patch
7 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.8
patch
Dependencies (37)
+ 29 more |
|
9.2.7
patch
10 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.7
patch
Dependencies (37)
+ 29 more |
|
9.2.6
patch
11 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.6
patch
Dependencies (37)
+ 29 more |
|
9.2.5
patch
11 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.5
patch
Dependencies (37)
+ 29 more |
|
9.2.4
patch
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.4
patch
Dependencies (37)
+ 29 more |
|
9.2.3
patch
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.3
patch
Dependencies (36)
+ 28 more |
|
9.2.2
patch
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.2
patch
Dependencies (37)
+ 29 more |
|
9.2.1
patch
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.1
patch
Dependencies (37)
+ 29 more |
|
9.2.0
minor
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.2.0
minor
Dependencies (37)
+ 29 more |
|
9.1.0
minor
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.1.0
minor
Dependencies (34)
+ 26 more |
|
9.0.1
patch
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.1
patch
Dependencies (34)
+ 26 more |
|
9.0.0
initial
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0
initial
Dependencies (34)
+ 26 more |
|
9.0.0.pre6
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre6
pre
Dependencies (30)
+ 22 more |
|
9.0.0.pre5
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre5
pre
Dependencies (30)
+ 22 more |
|
9.0.0.pre4
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre4
pre
Dependencies (31)
+ 23 more |
|
9.0.0.pre3
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre3
pre
Dependencies (31)
+ 23 more |
|
9.0.0.pre2
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre2
pre
Dependencies (32)
+ 24 more |
|
9.0.0.pre1
pre
14 CVEs
CVE-2024-39311
GHSA-8fm5-gg2f-f66q
Mar 28, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
Network
Low
High
SummaryA publisher on a DetailsA publisher on a We can create a redirect to a An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. PoCA publisher can create a new redirect as shown below. The payload used is An administrator will now see this redirect in their overview of the page.
If they click the link on the right, it triggers the XSS.
ImpactA publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Affected versions
10.0.0
10.0.1
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
+ 10 more Show less
9.2.1
9.2.10
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
10.0.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-0569
GHSA-g7gf-2rqw-5rwx
BIT-publify-2023-0569
Jan 29, 2023
Publify contains Weak Password Requirements
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1812
GHSA-rc42-jghf-vr8f
BIT-publify-2022-1812
Jan 14, 2023
Integer overflow in publify_core
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2023-0299
GHSA-q3rm-f527-ghxj
BIT-publify-2023-0299
Jan 14, 2023
Publify Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-2815
GHSA-79wq-g4v9-gfj4
BIT-publify-2022-2815
Jan 14, 2023
Publify Core does not strip metadata from images
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 7 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.2.9
Fixed in
9.2.10
References
Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25974
GHSA-wmh9-x28j-c6gr
BIT-publify-2021-25974
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2021-25975
GHSA-3h7v-wqw7-ff28
BIT-publify-2021-25975
May 24, 2022
Cross site scripting in publify
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References Updated Dec 06, 2023 · Source: OSV.dev
CVE-2022-1810
GHSA-c273-c6vg-4pv5
BIT-publify-2022-1810
May 24, 2022
Publify has Improper Access Controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A low-privileged user can modify and delete admin articles by changing the value of the Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1811
GHSA-3hwx-c6cp-q972
BIT-publify-2022-1811
May 24, 2022
Publify vulnerable to cross site scripting
9.1
/ 10
Critical
Network
Low
Low
None
Changed
Low
High
Low
Unrestricted file upload allowed the attacker to manipulate the request and bypass the protection of HTML files using a text file. Stored XSS may be obtained. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 6 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
Fixed in
9.2.9
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-1553
GHSA-5jm7-g527-m694
BIT-publify-2022-1553
May 17, 2022
Publify exposes article metadata
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0574
GHSA-79m3-q3wh-c3qm
BIT-publify-2022-0574
May 17, 2022
Publify Incorrect Authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0578
GHSA-w78q-4w34-jrjx
BIT-publify-2022-0578
May 17, 2022
Publify vulnerable to code injection
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Code Injection in GitHub repository publify/publify prior to 9.2.8. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 5 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
Fixed in
9.2.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0524
GHSA-x3rq-r3cm-5vc4
BIT-publify-2022-0524
Feb 09, 2022
Publify Business Logic Errors
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 4 more Show less
9.2.3
9.2.4
9.2.5
9.2.6
Fixed in
9.2.7
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-25973
GHSA-x24j-87x9-jvv5
BIT-publify-2021-25973
Nov 03, 2021
Publify `guest` role users can self-register even when the admin does not allow it
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. Affected versions
9.0.0
9.0.0.pre1
9.0.0.pre2
9.0.0.pre3
9.0.0.pre4
9.0.0.pre5
9.0.0.pre6
9.0.1
9.1.0
9.2.0
9.2.1
9.2.2
+ 2 more Show less
9.2.3
9.2.4
Fixed in
9.2.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
9.0.0.pre1
pre
Dependencies (32)
+ 24 more |


