Vulnerability index

Browse CVEs

44 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

TYPO3 MEDIUM 5.3
CVE-2024-55891

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c…

Mitigation only
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2010-3659

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1…

Mitigation only
Fix from $1,600 2017-10-20
TYPO3 HIGH 8.8
CVE-2017-14251

Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8…

No fix yet
Fix from $1,950 2017-09-11
TYPO3 MEDIUM 5.3
CVE-2017-6370

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv…

No fix yet
Fix from $1,600 2017-03-17
TYPO3 MEDIUM 6.1
CVE-2015-8760

The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 5.4
CVE-2015-8759

Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated edito…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 5.4
CVE-2015-8758

Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 6.1
CVE-2015-8757

Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 5.4
CVE-2015-8756

Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allo…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 5.4
CVE-2015-8755

Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote …

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 HIGH 7.5
CVE-2014-9509

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors…

No fix yet
Fix from $1,950 2015-01-04
TYPO3 MEDIUM 5.8
CVE-2014-3944

The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2014-06-03
TYPO3 MEDIUM 6.0
CVE-2014-3942

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authen…

Mitigation only
Fix from $1,600 2014-06-03
TYPO3 MEDIUM 5.0
CVE-2014-3941

TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspe…

Mitigation only
Fix from $1,600 2014-06-03
TYPO3 MEDIUM 6.5
CVE-2013-4250

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file exte…

Mitigation only
Fix from $1,600 2014-05-20
TYPO3 MEDIUM 6.5
CVE-2013-4321

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code…

Mitigation only
Fix from $1,600 2014-05-20
TYPO3 MEDIUM 5.5
CVE-2013-4320

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenti…

Mitigation only
Fix from $1,600 2014-05-20
TYPO3 MEDIUM 6.5
CVE-2013-7075

The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remot…

Mitigation only
Fix from $1,600 2013-12-23
TYPO3 MEDIUM 5.8
CVE-2013-7079

Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.…

Mitigation only
Fix from $1,600 2013-12-23
TYPO3 MEDIUM 5.8
CVE-2013-7080

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16…

Mitigation only
Fix from $1,600 2013-12-23
TYPO3 MEDIUM 6.5
CVE-2012-6144

SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote aut…

Mitigation only
Fix from $1,600 2013-07-01
TYPO3 MEDIUM 6.4
CVE-2013-1843

Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before …

Mitigation only
Fix from $1,600 2013-03-20
TYPO3 HIGH 7.5
CVE-2013-1842

SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 al…

Mitigation only
Fix from $1,950 2013-03-20
TYPO3 MEDIUM 5.0
CVE-2012-1605

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary …

Mitigation only
Fix from $1,600 2012-09-04
TYPO3 MEDIUM 5.0
CVE-2012-1607

The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attacker…

Mitigation only
Fix from $1,600 2012-09-04
TYPO3 MEDIUM 5.0
CVE-2012-1608

The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to…

Mitigation only
Fix from $1,600 2012-09-04
TYPO3 MEDIUM 6.8
CVE-2010-5099

The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 d…

No fix yet
Fix from $1,600 2012-05-30
TYPO3 MEDIUM 6.0
CVE-2010-5103

SQL injection vulnerability in the list module in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated u…

Mitigation only
Fix from $1,600 2012-05-21
TYPO3 MEDIUM 5.0
CVE-2010-5102

Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x…

Mitigation only
Fix from $1,600 2012-05-21
Beuserswitch MEDIUM 5.0
CVE-2012-1085

Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via …

No fix yet
Fix from $1,600 2012-02-14