---
id: CVE-2020-35854
title: >-
  Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body
  parameter.
summary: >-
  Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body
  parameter.
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: textpattern
product: textpattern
affected:
  - textpattern = 4.8.4
published: '2021-01-26'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-35854'
references:
  - url: >-
      https://riteshgohil-25.medium.com/textpattern-4-8-4-is-affected-by-cross-site-scripting-xss-in-the-body-parameter-b9a3d7da2a88
    label: cve@mitre.org
  - url: 'https://www.textpattern.co/demo'
    label: cve@mitre.org
  - url: 'http://textpattern.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://riteshgohil-25.medium.com/textpattern-4-8-4-is-affected-by-cross-site-scripting-xss-in-the-body-parameter-b9a3d7da2a88
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.textpattern.co/demo'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00571
epssPercentile: 0.4488
ingestedAt: '2026-07-05T02:00:01.363Z'
---

## Overview

Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

## Affected

- `textpattern = 4.8.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
