Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

TYPO3 MEDIUM 6.1
CVE-2021-21338

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been…

Fix: 6.2.57 / 7.6.51+
Fix from $1,600 2021-03-23
TYPO3 MEDIUM 5.4
CVE-2021-21340

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields…

Fix: 10.4.14 / 11.1.1+
Fix from $1,600 2021-03-23
TYPO3 MEDIUM 5.4
CVE-2021-21358

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Design…

Fix: 10.4.14 / 11.1.1+
Fix from $1,600 2021-03-23
TYPO3 MEDIUM 5.4
CVE-2021-21370

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discove…

Fix: 7.6.51 / 8.7.40+
Fix from $1,600 2021-03-23
TYPO3 HIGH 7.5
CVE-2020-26228

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in …

Fix: 9.5.23 / 10.4.10+
Fix from $1,950 2020-11-23
TYPO3 MEDIUM 6.1
CVE-2020-26227

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fl…

Fix: 6.2.54 / 7.6.48+
Fix from $1,600 2020-11-23
Fluid MEDIUM 6.1
CVE-2020-26216

TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities hav…

Fix: 2.0.8 / 2.1.7+
Fix from $1,600 2020-11-17
Fluid Engine MEDIUM 6.1
CVE-2020-15241

TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripti…

Fix: 2.0.5 / 2.1.4+
Fix from $1,600 2020-10-08
Mediace CRITICAL 9.8
CVE-2020-15086

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification…

Fix: 7.6.5+
Fix from $2,300 2020-07-29
TYPO3 HIGH 8.8
CVE-2020-15098

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
TYPO3 HIGH 8.1
CVE-2020-15099

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attack…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
TYPO3 CRITICAL 10.0
CVE-2020-11066

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on m…

Fix: 9.5.17 / 10.4.2+
Fix from $2,300 2020-05-14
TYPO3 HIGH 8.8
CVE-2020-11067

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to in…

Fix: after 10.4.1
Fix from $1,950 2020-05-14
TYPO3 HIGH 8.8
CVE-2020-11069

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable t…

Fix: after 10.4.1
Fix from $1,950 2020-05-14
TYPO3 MEDIUM 5.4
CVE-2020-11064

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered tha…

Fix: 9.5.17 / 10.4.2+
Fix from $1,600 2020-05-13
TYPO3 MEDIUM 5.4
CVE-2020-11065

In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered t…

Fix: 9.5.17 / 10.4.2+
Fix from $1,600 2020-05-13
Svg Sanitizer MEDIUM 5.4
CVE-2020-11070

The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is…

Fix: 1.0.3+
Fix from $1,600 2020-05-13
TYPO3 MEDIUM 6.1
CVE-2020-8091EPSS 5%

svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) atta…

Fix: 6.2.39+
Fix from $1,600 2020-01-27
TYPO3 HIGH 7.2
CVE-2019-19850

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, …

Fix: 8.7.30 / 9.5.12+
Fix from $1,950 2019-12-17
TYPO3 HIGH 8.8
CVE-2019-19849

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and…

Fix: 8.7.30 / 9.5.12+
Fix from $1,950 2019-12-17
TYPO3 HIGH 7.2
CVE-2019-19848

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually upl…

Fix: 8.7.30 / 9.5.12+
Fix from $1,950 2019-12-17
TYPO3 CRITICAL 9.8
CVE-2011-3583

It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a…

Fix: after 4.5.5
Fix from $2,300 2019-11-26
TYPO3 MEDIUM 6.5
CVE-2011-4900

TYPO3 before 4.5.4 allows Information Disclosure in the backend.

Fix: 4.5.4+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4901

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4902

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4904

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect…

Fix: 4.4.9 / 4.5.4+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.1
CVE-2011-4903

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 5.4
CVE-2011-4632

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 CRITICAL 9.8
CVE-2011-4628

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a …

Fix: 4.3.12 / 4.4.9+
Fix from $2,300 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4627

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06