← Back

Typo3

typo3

315 CVEs • 78 products

Products (78)

Click to collapse
Toggle
Typo3
typo3
Wt Gallery
wt_gallery
Ws Ecard
ws_ecard
Toi Category
toi_category
Terminal
terminal
Beuserswitch
beuserswitch
Sg Zfelib
sg_zfelib
Rlmp Eventdb
rlmp_eventdb
Send A Card
send_a_card
Phpmyadmin
phpmyadmin
Simplesurvey
simplesurvey
Econda Plugin
econda_plugin
Jobcontrol
jobcontrol
M1 Intern
m1_intern
Fsmi People
fsmi_people
Autobeuser
autobeuser
Nd Antispam
nd_antispam
Tjs Reslib
tjs_reslib
Xds Staff
xds_staff
Ttpedit
ttpedit
Vm19 Userlinks
vm19_userlinks
Mjseventpro
mjseventpro
Bb Simplejobs
bb_simplejobs
Job Reports
job_reports
Pb Clanlist
pb_clanlist
Majordomo
majordomo
Vd Gemomap
vd_gemomap
Ws Gallery
ws_gallery
Brainstorming
brainstorming
Sbanner
sbanner
Mm Whtppr
mm_whtppr
Skt Eurocalc
skt_eurocalc
Aeurltool
aeurltool
Flow
flow
Neos
neos
Svg Sanitizer
svg_sanitizer
Mediace
mediace
Fluid Engine
fluid_engine
Fluid
fluid

CVEs (315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Mm Whtppr
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Toi Category
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Toi Category
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a cra...Show more
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vulnerability than CVE-2010-3714.Show less
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, which allows remote atta...Show more
The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string, a related issue to CVE-2010-3710.Show less
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Re...Show more
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.Show less
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
7.1 HIGH· v2
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control de...Show more
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.Show less
1Typo3
1Sbanner
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Commerce Extension
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Typo3
Apr 29, 2026
May 11, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no suc...Show more
SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid parameter is generally used in third-party TYPO3 extensions - not in TYPO3 Core.Show less
1Typo3
1Typo3
Apr 29, 2026
Apr 20, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.
1Typo3
1Ws Ecard
Apr 29, 2026
Mar 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.
1Typo3
1Brainstorming
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Ws Ecard
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
1Typo3
1Ws Gallery
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Webesse Image Gallery (ws_gallery) extension 1.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Typo3
Apr 29, 2026
Feb 22, 2010
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both...Show more
Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.Show less
1Typo3
1Vd Gemomap
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the VD / Geomap (vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Mimi Tipfriends
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Majordomo
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.