← Back

Typo3

typo3

315 CVEs • 78 products

Products (78)

Click to collapse
Toggle
Typo3
typo3
Wt Gallery
wt_gallery
Ws Ecard
ws_ecard
Toi Category
toi_category
Terminal
terminal
Beuserswitch
beuserswitch
Sg Zfelib
sg_zfelib
Rlmp Eventdb
rlmp_eventdb
Send A Card
send_a_card
Phpmyadmin
phpmyadmin
Simplesurvey
simplesurvey
Econda Plugin
econda_plugin
Jobcontrol
jobcontrol
M1 Intern
m1_intern
Fsmi People
fsmi_people
Autobeuser
autobeuser
Nd Antispam
nd_antispam
Tjs Reslib
tjs_reslib
Xds Staff
xds_staff
Ttpedit
ttpedit
Vm19 Userlinks
vm19_userlinks
Mjseventpro
mjseventpro
Bb Simplejobs
bb_simplejobs
Job Reports
job_reports
Pb Clanlist
pb_clanlist
Majordomo
majordomo
Vd Gemomap
vd_gemomap
Ws Gallery
ws_gallery
Brainstorming
brainstorming
Sbanner
sbanner
Mm Whtppr
mm_whtppr
Skt Eurocalc
skt_eurocalc
Aeurltool
aeurltool
Flow
flow
Neos
neos
Svg Sanitizer
svg_sanitizer
Mediace
mediace
Fluid Engine
fluid_engine
Fluid
fluid

CVEs (315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the b...Show more
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
1Typo3
1Typo3
Nov 21, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
1Typo3
1Typo3
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
1Typo3
1Typo3
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
1Typo3
1Typo3
Jun 17, 2026
Jul 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
1Typo3
1Typo3
Jun 17, 2026
May 9, 2019
N/A· v4
7.5 HIGH· v3
9.3 HIGH· v2
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
5Debian
DrupalFedoraproject+2 more
5Debian Linux
DrupalFedora+2 more
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as de...Show more
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.Show less
1Typo3
1Pharstreamwrapper
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protecti...Show more
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.Show less
1Typo3
1Typo3
Jun 17, 2026
Apr 8, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
1Typo3
1Typo3
May 13, 2026
Oct 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web scrip...Show more
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms.Show less
1Typo3
1Typo3
May 13, 2026
Sep 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a...Show more
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.Show less
1Typo3
1Typo3
May 13, 2026
Mar 17, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the useride...Show more
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.Show less
1Typo3
1Typo3
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.
1Typo3
1Typo3
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
1Typo3
1Typo3
May 6, 2026
Jan 8, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."
1Typo3
1Typo3
May 6, 2026
Jan 8, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.