Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2021-21357

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass r…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21355

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to co…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21340

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21339

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21338

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handlin…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26229

Published Nov 23, 2020

TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity proce…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-26228

Published Nov 23, 2020

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26227

Published Nov 23, 2020

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vuln…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26216

Published Nov 17, 2020

TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities have been detected in Fluid: 1. T…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15241

Published Oct 8, 2020

TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the tern…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15099

Published Jul 29, 2020

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15098

Published Jul 29, 2020

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification me…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15086

Published Jul 29, 2020

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to gene…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11069

Published May 14, 2020

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery.…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11067

Published May 14, 2020

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In com…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11066

Published May 14, 2020

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted conten…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11065

Published May 13, 2020

In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typ…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11064

Published May 13, 2020

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11063

Published May 13, 2020

In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacke…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11070

Published May 13, 2020

The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8091

Published Jan 27, 2020

svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19850

Published Dec 17, 2019

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19849

Published Dec 17, 2019

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19848

Published Dec 17, 2019

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extensio…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3583

Published Nov 26, 2019

It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 76-100 of 518 CVEsPage 4 of 21