← Back

Typo3

typo3

315 CVEs • 78 products

Products (78)

Click to collapse
Toggle
Typo3
typo3
Wt Gallery
wt_gallery
Ws Ecard
ws_ecard
Toi Category
toi_category
Terminal
terminal
Beuserswitch
beuserswitch
Sg Zfelib
sg_zfelib
Rlmp Eventdb
rlmp_eventdb
Send A Card
send_a_card
Phpmyadmin
phpmyadmin
Simplesurvey
simplesurvey
Econda Plugin
econda_plugin
Jobcontrol
jobcontrol
M1 Intern
m1_intern
Fsmi People
fsmi_people
Autobeuser
autobeuser
Nd Antispam
nd_antispam
Tjs Reslib
tjs_reslib
Xds Staff
xds_staff
Ttpedit
ttpedit
Vm19 Userlinks
vm19_userlinks
Mjseventpro
mjseventpro
Bb Simplejobs
bb_simplejobs
Job Reports
job_reports
Pb Clanlist
pb_clanlist
Majordomo
majordomo
Vd Gemomap
vd_gemomap
Ws Gallery
ws_gallery
Brainstorming
brainstorming
Sbanner
sbanner
Mm Whtppr
mm_whtppr
Skt Eurocalc
skt_eurocalc
Aeurltool
aeurltool
Flow
flow
Neos
neos
Svg Sanitizer
svg_sanitizer
Mediace
mediace
Fluid Engine
fluid_engine
Fluid
fluid

CVEs (315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Nd Antispam
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors.
1Typo3
1Wt Gallery
Apr 23, 2026
Apr 7, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and determine directory structure via unspecified vectors.
1Typo3
1Pmk Rssnewsexport Extension
Apr 23, 2026
Apr 3, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Autobeuser
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Typo3
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbit...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.Show less
1Typo3
1Typo3
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attack...Show more
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.Show less
1Typo3
1Tu Clausthal Staff
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Tu Clausthal Odin
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the TU-Clausthal ODIN (tuc_odin) extension 0.0.1, 0.1.0, 0.1.1, and 0.2.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Sb Universal Plugin
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the SB Universal Plugin (SBuniplug) extension 2.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Wec Discussion Forum
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Wec Discussion Forum
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029.Show less
1Typo3
1Freecap Captcha Extension
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containi...Show more
The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.Show less
1Typo3
1Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) conten...Show more
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.Show less
1Typo3
1Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1...Show more
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.Show less
2Debian
Typo3
2Debian Linux
Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the...Show more
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.Show less
1Typo3
1Dictionary Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
1Typo3
2Fsmi People
Wir Ber Uns Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Wir Ber Uns Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Cms Poll System Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.