Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

TYPO3 MEDIUM 6.1
CVE-2011-4626

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 5.4
CVE-2011-4629

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 5.4
CVE-2011-4630

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 5.4
CVE-2011-4631

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script …

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2010-3671

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attacker…

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-05
TYPO3 MEDIUM 6.1
CVE-2010-3672

TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.

Fix: 4.3.4 / 4.4.1+
Fix from $1,600 2019-11-05
TYPO3 MEDIUM 6.1
CVE-2010-3674

TYPO3 before 4.4.1 allows XSS in the frontend search box.

Fix: 4.4.1+
Fix from $1,600 2019-11-05
TYPO3 MEDIUM 5.3
CVE-2010-3673

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.

Fix: 4.2.13 / 4.3.4+
Fix from $1,600 2019-11-05
TYPO3 HIGH 7.5
CVE-2010-3668

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.

Fix: 4.1.14 / 4.2.13+
Fix from $1,950 2019-11-04
TYPO3 MEDIUM 5.4
CVE-2010-3669

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

Fix: 4.2.13 / 4.3.4+
Fix from $1,600 2019-11-04
TYPO3 HIGH 8.8
CVE-2010-3662

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,950 2019-11-04
TYPO3 HIGH 8.8
CVE-2010-3663

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPatter…

Fix: 4.1.14 / 4.2.13+
Fix from $1,950 2019-11-04
TYPO3 MEDIUM 6.5
CVE-2010-3664

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
TYPO3 MEDIUM 5.4
CVE-2010-3665

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
TYPO3 MEDIUM 5.3
CVE-2010-3666

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
TYPO3 MEDIUM 5.3
CVE-2010-3667

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
TYPO3 MEDIUM 6.1
CVE-2010-3661

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-01
TYPO3 MEDIUM 5.4
CVE-2010-3660

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-01
TYPO3 HIGH 8.8
CVE-2019-12747

TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.

Fix: after 9.5.7
Fix from $1,950 2019-07-09
TYPO3 MEDIUM 6.1
CVE-2019-12748

TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.

Fix: after 9.5.7
Fix from $1,600 2019-07-09
TYPO3 HIGH 7.5
CVE-2019-11832

TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image proc…

Fix: 8.7.25 / 9.5.6+
Fix from $1,950 2019-05-09
Pharstreamwrapper CRITICAL 9.8
CVE-2019-11831EPSS 6%

The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which a…

Fix: 2.1.1 / 3.1.1+
Fix from $2,300 2019-05-09
Pharstreamwrapper CRITICAL 9.8
CVE-2019-11830

PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar st…

Fix: 2.1.1 / 3.1.1+
Fix from $2,300 2019-05-09
TYPO3 MEDIUM 5.4
CVE-2010-3659

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1…

Mitigation only
Fix from $1,600 2017-10-20
TYPO3 HIGH 8.8
CVE-2017-14251

Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8…

No fix yet
Fix from $1,950 2017-09-11
TYPO3 MEDIUM 5.3
CVE-2017-6370

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv…

No fix yet
Fix from $1,600 2017-03-17
TYPO3 HIGH 8.1
CVE-2016-5091

Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitra…

Fix: after 6.2.23
Fix from $1,950 2017-01-23
TYPO3 MEDIUM 6.1
CVE-2016-4056

Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script…

Patch available
Fix from $1,600 2017-01-23
TYPO3 MEDIUM 6.1
CVE-2015-8760

The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka…

Mitigation only
Fix from $1,600 2016-01-08
TYPO3 MEDIUM 5.4
CVE-2015-8759

Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated edito…

Mitigation only
Fix from $1,600 2016-01-08