typo3

346 tracked vulnerabilities.

CVE-2022-23501 MEDIUM
TYPO3 < 8.7.49, 9.5.38, 10.4.33, 11.5.20, 12.1.1 - Improper Authentication via Username Ambiguity
Dec 14, 2022
CVSS 5.9
EPSS 0.00
CVE-2022-23500 MEDIUM
TYPO3 <9.5.38, 10.4.33, 11.5.20, 12.1.1 - DoS
Dec 14, 2022
CVSS 5.9
EPSS 0.00
CVE-2022-23499 MEDIUM
TYPO3 html_sanitizer < 1.5.0 and 2.0.0-2.0.10 - Cross-Site Scripting via CDATA Section Bypass
Dec 13, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-36108 MEDIUM
TYPO3 10.0.0-10.4.31 - Cross-Site Scripting via f:asset.css View Helper
Sep 13, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-36107 MEDIUM
TYPO3 7.0.0-7.6.57, 10.0.0-10.4.31 - Authenticated Cross-Site Scripting in FileDumpController
Sep 13, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-36106 MEDIUM
TYPO3 <10.4.31, <11.5.15 - Info Disclosure
Sep 13, 2022
CVSS 5.4
EPSS 0.00
CVE-2022-36105 MEDIUM
TYPO3 7.0.0-7.6.57, 10.0.0-10.4.31 - User Enumeration via Authentication Timing Discrepancy
Sep 13, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-36104 MEDIUM
TYPO3 CMS 11.4.0 through 11.5.15 - Denial of Service via Recursive Page Error Handler
Sep 13, 2022
CVSS 5.9
EPSS 0.01
CVE-2022-36020 MEDIUM
typo3/html-sanitizer < 1.0.7 - Cross-Site Scripting via HTML Comment Parsing Bypass
Sep 13, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-31050 MEDIUM
TYPO3 <9.5.34 ELTS, <10.4.29, <11.5.11 - Info Disclosure
Jun 14, 2022
CVSS 6.0
EPSS 0.00
CVE-2022-31049 MEDIUM
TYPO3 <9.5.34 ELTS, <10.4.29, <11.5.11 - Info Disclosure
Jun 14, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-31048 MEDIUM
TYPO3 <8.7.47 ELTS, <9.5.34 ELTS, <10.4.29, <11.5.11 - XSS
Jun 14, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-31047 MEDIUM
TYPO3 <7.6.57 ELTS, <8.7.47 ELTS, <9.5.34 ELTS, <10.4.29, <11.5.11 ...
Jun 14, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-31046 MEDIUM
TYPO3 <7.6.57 ELTS, <8.7.47 ELTS, <9.5.34 ELTS, <10.4.29, <11.5.11 ...
Jun 14, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-41114 MEDIUM
TYPO3 11.0.0-11.5.0 - Host Header Spoofing via trustedHostsPattern Regression
Oct 05, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-41113 HIGH
TYPO3 11.2.0-11.4.99 - Cross-Site Request Forgery via Deep Link Sharing
Oct 05, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-32768 MEDIUM
TYPO3 7.0.0-7.6.52, 9.0.0-9.5.28, 10.0.0-10.4.19 - Cross-Site Scripting via Rich-Text Content Rendering
Aug 10, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-32767 MEDIUM
TYPO3 <9.5.27, <10.4.17, <11.3.0 - Info Disclosure
Jul 20, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-32669 MEDIUM
TYPO3 9.0.0-9.5.28 10.0.0-10.4.17 11.0.0-11.3.0 - Authenticated Stored Cross-Site Scripting in Backend Layout Grid View
Jul 20, 2021
CVSS 6.4
EPSS 0.00
CVE-2021-32668 MEDIUM
TYPO3 9.0.0-9.5.28, 10.0.0-10.4.17, 11.0.0-11.3.0 - Authenticated XSS in QueryGenerator and QueryView
Jul 20, 2021
CVSS 6.4
EPSS 0.00
CVE-2021-32667 MEDIUM
TYPO3 9.0.0-9.5.28, 10.0.0-10.4.17, 11.0.0-11.3.0 - Authenticated Stored Cross-Site Scripting in Page TSconfig
Jul 20, 2021
CVSS 6.4
EPSS 0.00
CVE-2021-21365 MEDIUM
Typo3 < 7.1.2 - XSS
Apr 27, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21370 MEDIUM
TYPO3 < 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 - Authenticated Cross-Site Scripting in Menu Content Element Preview
Mar 23, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21359 MEDIUM
TYPO3 <9.5.25, 10.4.14, 11.1.1 - DoS
Mar 23, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-21358 MEDIUM
TYPO3 < 10.4.14 - Authenticated Stored Cross-Site Scripting in Form Designer Module
Mar 23, 2021
CVSS 5.4
EPSS 0.00