typo3

346 tracked vulnerabilities.

CVE-2014-3944
TYPO3 6.2.0-6.2.2 - Improper Authentication
Jun 03, 2014
EPSS 0.00
CVE-2014-3943
TYPO3 4.5.0-4.5.33, 4.7.0-4.7.18, 6.0.0-6.0.13, 6.1.0-6.1.8, 6.2.0-6.2.2 - Authenticated Cross-Site Scripting
Jun 03, 2014
EPSS 0.00
CVE-2014-3942
TYPO3 4.5.0-4.5.33, 4.7.0-4.7.18, 6.0.0-6.0.13, 6.1.0-6.1.8 - Remote Code Execution via Color Picker Wizard
Jun 03, 2014
EPSS 0.00
CVE-2014-3941
TYPO3 <4.5.34-6.2.3 - Info Disclosure
Jun 03, 2014
EPSS 0.00
CVE-2013-4321
TYPO3 6.0.0-6.0.8 and 6.1.0-6.1.3 - Authenticated Remote Code Execution via File Extension in FAL Renaming
May 20, 2014
EPSS 0.00
CVE-2013-4320
TYPO3 6.0.0-6.0.8 and 6.1.0-6.1.3 - Authenticated Arbitrary File Read and Write via File Abstraction Layer
May 20, 2014
EPSS 0.00
CVE-2013-4250
TYPO3 6.0.0-6.0.7 and 6.1.0-6.1.2 - Authenticated Arbitrary PHP Code Execution via File Upload
May 20, 2014
EPSS 0.00
CVE-2013-7341
Flowplayer Flash <3.2.17 - XSS
Mar 24, 2014
EPSS 0.00
CVE-2013-7078
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - Cross-Site Scripting via Error Message
Jan 19, 2014
EPSS 0.00
CVE-2013-7081
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - HMAC Signature Bypass
Dec 23, 2013
EPSS 0.00
CVE-2013-7080
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11 - Unauthenticated Mass Assignment via Extension Table Administration
Dec 23, 2013
EPSS 0.00
CVE-2013-7079
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - Open Redirect in OpenID Extension
Dec 23, 2013
EPSS 0.00
CVE-2013-7075
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - Authenticated PHP Object Unserialization and File Deletion
Dec 23, 2013
EPSS 0.00
CVE-2013-7073
TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - Authenticated Data Read via Content Editing Wizards
Dec 23, 2013
EPSS 0.00
CVE-2013-7082
TYPO3 Flow 1.1.x < 1.1.1 and 2.0.x < 2.0.1 - Cross-Site Scripting via Error Action Method
Dec 21, 2013
EPSS 0.00
CVE-2013-7077
TYPO3 6.0.0-6.0.11 and 6.1.0-6.1.6 - Cross-Site Scripting in Backend User Administration Module
Dec 21, 2013
EPSS 0.00
CVE-2013-7076
TYPO3 4.5.x-4.7.x - Cross-Site Scripting in Extension Manager
Dec 21, 2013
EPSS 0.00
CVE-2013-7074
TYPO3 4.5.x-4.5.31, 4.7.x-4.7.16, 6.0.x-6.0.11, 6.1.x-6.1.6 - Authenticated XSS in Content Editing Wizards
Dec 21, 2013
EPSS 0.00
CVE-2013-4701
PHP OpenID Library <2.2.2 - Info Disclosure/DoS
Aug 21, 2013
EPSS 0.01
CVE-2013-1843
TYPO3 4.5.x-4.6.x, 4.7.x-4.7.8, 6.0.x-6.0.2 - Open Redirect via Access Tracking Mechanism
Mar 20, 2013
EPSS 0.01
CVE-2013-1842
TYPO3 4.5.x-4.6.x-4.7.x-6.0.x - SQL Injection via Query Object Model
Mar 20, 2013
EPSS 0.03
CVE-2012-6146
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated Arbitrary Record History Access
May 20, 2014
EPSS 0.00
CVE-2012-6148
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated Cross-Site Scripting in Function Menu API
Jul 01, 2013
EPSS 0.00
CVE-2012-6147
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated Cross-Site Scripting in TCA-Tree Backend API
Jul 01, 2013
EPSS 0.00
CVE-2012-6145
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated Cross-Site Scripting in Backend History Module
Jul 01, 2013
EPSS 0.00