typo3

346 tracked vulnerabilities.

CVE-2021-21357 HIGH
TYPO3 < 8.7.40, 9.5.25, 10.4.14, 11.1.1 - Authenticated Path Traversal and Arbitrary File Write via Form Designer Module
Mar 23, 2021
CVSS 8.3
EPSS 0.01
CVE-2021-21355 HIGH
TYPO3 <8.7.40, 9.5.25, 10.4.14, 11.1.1 - Info Disclosure
Mar 23, 2021
CVSS 8.6
EPSS 0.00
CVE-2021-21340 MEDIUM
TYPO3 10.0.0-10.4.13 - Authenticated Stored Cross-Site Scripting in Description Column Preview
Mar 23, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21339 MEDIUM
TYPO3 < 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 - Cleartext Session Identifiers
Mar 23, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-21338 MEDIUM
TYPO3 < 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 - Unauthenticated Open Redirect via Login Handling
Mar 23, 2021
CVSS 4.7
EPSS 0.00
CVE-2020-26229 LOW
TYPO3 10.4.0-10.4.9 - Authenticated XML External Entity Injection in RSS Widgets
Nov 23, 2020
CVSS 3.7
EPSS 0.00
CVE-2020-26228 HIGH
TYPO3 9.0.0-9.5.22 and 10.0.0-10.4.9 - Cleartext Storage of Sensitive Information
Nov 23, 2020
CVSS 8.1
EPSS 0.00
CVE-2020-26227 MEDIUM
TYPO3 6.2.0-6.2.53, 9.0.0-9.5.22, 10.0.0-10.4.9 - Cross-Site Scripting via Fluid View Helper Argument
Nov 23, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-26216 HIGH
TYPO3 Fluid < 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11, 2.6.10 - Cross-Site Scripting
Nov 17, 2020
CVSS 8.0
EPSS 0.01
CVE-2020-15241 MEDIUM
TYPO3 Fluid Engine <2.0.5-2.6.1 - XSS
Oct 08, 2020
CVSS 4.7
EPSS 0.00
CVE-2020-15099 HIGH
TYPO3 CMS >=9.0.0 <9.5.20, >=10.0.0 <10.4.6 - Info Disclosure
Jul 29, 2020
CVSS 8.1
EPSS 0.01
CVE-2020-15098 HIGH
TYPO3 CMS >=9.0.0 <9.5.20, >=10.0.0 <10.4.6 - RCE
Jul 29, 2020
CVSS 8.8
EPSS 0.02
CVE-2020-15086 CRITICAL
mediace 7.6.2-7.6.4 - Authenticated Remote Code Execution via Checksum Verification Bypass
Jul 29, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-11069 HIGH
TYPO3 CMS 9.0.0-9.5.16 and 10.0.0-10.4.1 - Same-Site Request Forgery via Malicious Uploaded Resource
May 14, 2020
CVSS 8.0
EPSS 0.00
CVE-2020-11067 HIGH
TYPO3 CMS <9.5.16, <10.4.1 - Code Injection
May 14, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-11066 HIGH
TYPO3 CMS >=9.0.0 <9.5.17, >=10.0.0 <10.4.2 - Code Injection
May 14, 2020
CVSS 8.7
EPSS 0.01
CVE-2020-11065 MEDIUM
TYPO3 CMS >=9.5.12 <9.5.17, >=10.2.0 <10.4.2 - XSS
May 13, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-11064 MEDIUM
TYPO3 CMS >=9.0.0 <9.5.17, >=10.0.0 <10.4.2 - XSS
May 13, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-11063 LOW
TYPO3 CMS <10.4.1 - Info Disclosure
May 13, 2020
CVSS 3.7
EPSS 0.00
CVE-2020-11070 MEDIUM
TYPO3 SVG Sanitizer < 1.0.3 - Cross-Site Scripting via Invalid SVG Markup
May 13, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-8091 MEDIUM
TYPO3 6.2.0-6.2.38 ELTS and 7.0.0-7.1.0 - Unauthenticated Cross-Site Scripting via svg.swf
Jan 27, 2020
CVSS 6.1
EPSS 0.21
CVE-2019-19850 HIGH
TYPO3 < 8.7.30 - Authenticated SQL Injection in QueryGenerator
Dec 17, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-19849 HIGH
TYPO3 < 8.7.30, 9.x < 9.5.12, 10.x < 10.2.2 - Authenticated Remote Code Execution via Insecure Deserialization
Dec 17, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-19848 HIGH
TYPO3 < 8.7.30, 9.x < 9.5.12, 10.x < 10.2.2 - Authenticated Path Traversal via Extension Manager ZIP Extraction
Dec 17, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-12748 MEDIUM
TYPO3 8.3.0-8.7.26 and 9.0.0-9.5.7 - Cross-Site Scripting
Jul 09, 2019
CVSS 6.1
EPSS 0.00