← Back

Typo3

typo3

315 CVEs • 78 products

Products (78)

Click to collapse
Toggle
Typo3
typo3
Wt Gallery
wt_gallery
Ws Ecard
ws_ecard
Toi Category
toi_category
Terminal
terminal
Beuserswitch
beuserswitch
Sg Zfelib
sg_zfelib
Rlmp Eventdb
rlmp_eventdb
Send A Card
send_a_card
Phpmyadmin
phpmyadmin
Simplesurvey
simplesurvey
Econda Plugin
econda_plugin
Jobcontrol
jobcontrol
M1 Intern
m1_intern
Fsmi People
fsmi_people
Autobeuser
autobeuser
Nd Antispam
nd_antispam
Tjs Reslib
tjs_reslib
Xds Staff
xds_staff
Ttpedit
ttpedit
Vm19 Userlinks
vm19_userlinks
Mjseventpro
mjseventpro
Bb Simplejobs
bb_simplejobs
Job Reports
job_reports
Pb Clanlist
pb_clanlist
Majordomo
majordomo
Vd Gemomap
vd_gemomap
Ws Gallery
ws_gallery
Brainstorming
brainstorming
Sbanner
sbanner
Mm Whtppr
mm_whtppr
Skt Eurocalc
skt_eurocalc
Aeurltool
aeurltool
Flow
flow
Neos
neos
Svg Sanitizer
svg_sanitizer
Mediace
mediace
Fluid Engine
fluid_engine
Fluid
fluid

CVEs (315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Zak Store Management
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Pb Clanlist
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Job Reports
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Bb Simplejobs
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Mjseventpro
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Vm19 Userlinks
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Ttpedit
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Dl3 Tt News Alerts
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Kiddog Mysqldumper
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.
1Typo3
1Xds Staff
Apr 23, 2026
Dec 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web s...Show more
Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbi...Show more
Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the sanitizing algorithm.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote...Show more
SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
8.5 HIGH· v2
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arb...Show more
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via craf...Show more
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, related to a "frame hijacking" issue.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.Show less
1Typo3
1Typo3
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content...Show more
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.Show less
1Typo3
2Tjs Reslib
Typo3
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Resource Library (tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.