Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powermail HIGH 7.5
CVE-2024-47047

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting i…

Fix: after 12.4.0
Fix from $1,950 2024-09-17
Powermail CRITICAL 9.8
CVE-2024-45233

An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missi…

Fix: 7.5.0 / 8.5.0+
Fix from $2,300 2024-08-29
Powermail MEDIUM 5.3
CVE-2024-45232

An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting…

Fix: 7.5.0 / 8.5.0+
Fix from $1,600 2024-08-29
Femanager MEDIUM 5.3
CVE-2022-44543

The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if the…

Fix: 5.5.2 / 6.3.3+
Fix from $1,600 2023-12-12
Femanager HIGH 7.5
CVE-2023-25013

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…

Fix: 5.5.3 / 6.3.4+
Fix from $1,950 2023-02-02
Femanager HIGH 7.5
CVE-2023-25014

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…

Fix: 5.5.3 / 6.3.4+
Fix from $1,950 2023-02-02
Living User Experience CRITICAL 9.8
CVE-2022-35628EPSS 26%

A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

Fix: 17.6.1 / 24.0.2+
Fix from $2,300 2022-07-12
Femanager MEDIUM 5.4
CVE-2021-36787

The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

Fix: 5.5.1 / 6.3.1+
Fix from $1,600 2021-08-13
Femanager MEDIUM 6.4
CVE-2014-6292

The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified v…

Fix: after 1.0.8
Fix from $1,600 2014-10-03