Filtered by vendor Typo3
Subscribe
Total
477 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-3661 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 5.8 MEDIUM | 6.1 MEDIUM |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend. | |||||
CVE-2010-3668 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl. | |||||
CVE-2011-4902 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 5.5 MEDIUM | 6.5 MEDIUM |
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver. | |||||
CVE-2010-3667 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. | |||||
CVE-2011-4632 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message. | |||||
CVE-2011-4900 | 2 Debian, Typo3 | 2 Debian Linux, Typo3 | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
TYPO3 before 4.5.4 allows Information Disclosure in the backend. | |||||
CVE-2011-4903 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function. | |||||
CVE-2019-19848 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.) | |||||
CVE-2019-11831 | 5 Debian, Drupal, Fedoraproject and 2 more | 5 Debian Linux, Drupal, Fedora and 2 more | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL. | |||||
CVE-2019-11832 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 9.3 HIGH | 7.5 HIGH |
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick. | |||||
CVE-2019-12747 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 6.5 MEDIUM | 8.8 HIGH |
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. | |||||
CVE-2019-11830 | 1 Typo3 | 1 Pharstreamwrapper | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism. | |||||
CVE-2019-12748 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. | |||||
CVE-2018-6905 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process. | |||||
CVE-2017-14251 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 6.5 MEDIUM | 8.8 HIGH |
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code. | |||||
CVE-2010-3659 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms. | |||||
CVE-2017-6370 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields. | |||||
CVE-2016-5091 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 6.8 MEDIUM | 8.1 HIGH |
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action. | |||||
CVE-2016-4056 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark. | |||||
CVE-2015-8757 | 1 Typo3 | 1 Typo3 | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation. |