Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-49967.json"