Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2011-4626 Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script … TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 5.4 CVE-2011-4629 Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script … TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 5.4 CVE-2011-4630 Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script … TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 5.4 CVE-2011-4631 Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script … TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 6.5 CVE-2010-3671 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attacker… TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-05 MEDIUM 6.1 CVE-2010-3672 TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension. TYPO3 4.3.4 / 4.4.1+ Fix from $1,6002019-11-05 MEDIUM 6.1 CVE-2010-3674 TYPO3 before 4.4.1 allows XSS in the frontend search box. TYPO3 4.4.1+ Fix from $1,6002019-11-05 MEDIUM 5.3 CVE-2010-3673 TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API. TYPO3 4.2.13 / 4.3.4+ Fix from $1,6002019-11-05 HIGH 7.5 CVE-2010-3668 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl. TYPO3 4.1.14 / 4.2.13+ Fix from $1,9502019-11-04 MEDIUM 5.4 CVE-2010-3669 TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box. TYPO3 4.2.13 / 4.3.4+ Fix from $1,6002019-11-04 HIGH 8.8 CVE-2010-3662 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend. TYPO3 4.1.14 / 4.2.13+ Fix from $1,9502019-11-04 HIGH 8.8 CVE-2010-3663 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPatter… TYPO3 4.1.14 / 4.2.13+ Fix from $1,9502019-11-04 MEDIUM 6.5 CVE-2010-3664 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-04 MEDIUM 5.4 CVE-2010-3665 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-04 MEDIUM 5.3 CVE-2010-3666 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-04 MEDIUM 5.3 CVE-2010-3667 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-04 MEDIUM 6.1 CVE-2010-3661 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-01 MEDIUM 5.4 CVE-2010-3660 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend. TYPO3 4.1.14 / 4.2.13+ Fix from $1,6002019-11-01 HIGH 8.8 CVE-2019-12747 TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. TYPO3 after 9.5.7 Fix from $1,9502019-07-09 MEDIUM 6.1 CVE-2019-12748 TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. TYPO3 after 9.5.7 Fix from $1,6002019-07-09 HIGH 7.5 CVE-2019-11832 TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image proc… TYPO3 8.7.25 / 9.5.6+ Fix from $1,9502019-05-09 CRITICAL 9.8 CVE-2019-11831EPSS 6% The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which a… Pharstreamwrapper 2.1.1 / 3.1.1+ Fix from $2,3002019-05-09 CRITICAL 9.8 CVE-2019-11830 PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar st… Pharstreamwrapper 2.1.1 / 3.1.1+ Fix from $2,3002019-05-09 MEDIUM 5.4 CVE-2010-3659 Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1… TYPO3 Mitigation only Fix from $1,6002017-10-20 HIGH 8.8 CVE-2017-14251 Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8… TYPO3 No fix yet Fix from $1,9502017-09-11 MEDIUM 5.3 CVE-2017-6370 TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv… TYPO3 No fix yet Fix from $1,6002017-03-17 HIGH 8.1 CVE-2016-5091 Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitra… TYPO3 after 6.2.23 Fix from $1,9502017-01-23 MEDIUM 6.1 CVE-2016-4056 Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script… TYPO3 Patch available Fix from $1,6002017-01-23 MEDIUM 6.1 CVE-2015-8760 The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka… TYPO3 Mitigation only Fix from $1,6002016-01-08 MEDIUM 5.4 CVE-2015-8759 Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated edito… TYPO3 Mitigation only Fix from $1,6002016-01-08