Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2011-4904

Published Nov 6, 2019

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4903

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS func…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4902

Published Nov 6, 2019

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4901

Published Nov 6, 2019

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4632

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4631

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extensi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4630

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links w…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4629

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4628

Published Nov 6, 2019

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4627

Published Nov 6, 2019

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4626

Published Nov 6, 2019

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" pro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3673

Published Nov 5, 2019

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3672

Published Nov 5, 2019

TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3671

Published Nov 5, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3670

Published Nov 5, 2019

TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3669

Published Nov 4, 2019

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3668

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3667

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3666

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3665

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3664

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3663

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3662

Published Nov 4, 2019

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 518 CVEsPage 5 of 21