Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2013-4682

Published Jun 25, 2013

SQL injection vulnerability in the Multishop extension before 2.0.39 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4680

Published Jun 25, 2013

Open redirect vulnerability in Maag Form Captcha extension 2.0.0 and earlier for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1843

Published Mar 20, 2013

Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1842

Published Mar 20, 2013

SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5889

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5888

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3531

Published Sep 5, 2012

Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3530

Published Sep 5, 2012

Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3529

Published Sep 5, 2012

The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3528

Published Sep 5, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow remote authenticated backend user…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3527

Published Sep 5, 2012

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrar…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1608

Published Sep 4, 2012

The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1607

Published Sep 4, 2012

The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1606

Published Sep 4, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote au…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1605

Published Sep 4, 2012

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2112

Published Aug 27, 2012

Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5099

Published May 30, 2012

The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5104

Published May 21, 2012

The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_B…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5103

Published May 21, 2012

SQL injection vulnerability in the list module in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated users with certain permissions…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5102

Published May 21, 2012

Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5101

Published May 21, 2012

Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to re…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 518 CVEsPage 9 of 21