typo3
346 tracked vulnerabilities.
CVE-2012-6144
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated SQL Injection
Jul 01, 2013
EPSS 0.01
CVE-2012-3531
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Cross-Site Scripting in Install Tool
Sep 05, 2012
EPSS 0.00
CVE-2012-3530
TYPO3 4.5.x < 4.5.19, 4.6.x < 4.6.12, 4.7.x < 4.7.4 - Cross-Site Scripting via HTML5 JavaScript Events
Sep 05, 2012
EPSS 0.01
CVE-2012-3529
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Authenticated Encryption Key Exposure
Sep 05, 2012
EPSS 0.00
CVE-2012-3528
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Authenticated Cross-Site Scripting
Sep 05, 2012
EPSS 0.01
CVE-2012-3527
TYPO3 4.5.0-4.5.18 - Authenticated Remote Code Execution via Unsafe Deserialization in Backend Help System
Sep 05, 2012
EPSS 0.02
CVE-2012-1608
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Cross-Site Scripting Bypass via Non-Printable Characters
Sep 04, 2012
EPSS 0.01
CVE-2012-1607
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Unauthenticated Database Name Exposure via CLI Script
Sep 04, 2012
EPSS 0.01
CVE-2012-1606
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Authenticated Cross-Site Scripting
Sep 04, 2012
EPSS 0.00
CVE-2012-1605
TYPO3 4.6.0-4.6.6, 4.7, 6.0 - Remote Code Execution via Extbase Framework Unserialization
Sep 04, 2012
EPSS 0.01
CVE-2012-2112
TYPO3 4.4.0-4.4.14, 4.5.0-4.5.14, 4.6.0-4.6.7, 4.7 - Cross-Site Scripting via Exception Handler
Aug 27, 2012
EPSS 0.01
CVE-2012-1086
TYPO3 aeurltool 0.1.0 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1085
TYPO3 beuserswitch <0.0.1 - Info Disclosure
Feb 14, 2012
EPSS 0.00
CVE-2012-1084
TYPO3 BE User Switch 0.0.1 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1083
TYPO3 Terminal < 0.3.2 - Cross-Site Request Forgery
Feb 14, 2012
EPSS 0.00
CVE-2012-1082
Terminal PHP Shell < 0.3.2 - Authenticated Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1080
skt_eurocalc 0.0.1 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1074
TYPO3 mm_whtppr <0.0.4 - SQL Injection
Feb 14, 2012
EPSS 0.00
CVE-2012-1073
TYPO3 toi_category < 0.6.0 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1072
TYPO3 toi_category <0.6.0 - SQL Injection
Feb 14, 2012
EPSS 0.00
CVE-2011-3583
CRITICAL
Typo3 4.5.0-4.5.5 - SQL Injection via Prepared Statement Parameter Binding
Nov 26, 2019
CVSS 9.8
EPSS 0.00
CVE-2011-4904
MEDIUM
TYPO3 < 4.4.9 and 4.5.x < 4.5.4 - Unauthenticated Information Disclosure via ExtDirect Endpoint
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4903
MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Cross-Site Scripting via RemoveXSS Function
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2011-4902
MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Arbitrary File Deletion
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4901
MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Unauthenticated Database Information Disclosure
Nov 06, 2019
CVSS 6.5
EPSS 0.00
Products
typo3 218
cms 116
cms-core 85
cms-backend 22
cms-install 6
cms-form 4
cms-frontend 4
dam_frontend_extension 4
html-sanitizer 4
html_sanitizer 4
wec_discussion_forum 4
Extension "Faceted Search" 3
pdf_generator_2_extension 3
Extension "Mailqueue" 2
address_directory 2
air_filemanager 2
beuserswitch 2
cms-beuser 2
cms-dashboard 2
cms-recycler 2
cms-workspaces 2
commerce_extension 2
eluna_page_comments_extension 2
ns backup extension 2
phar-stream-wrapper 2
pharstreamwrapper 2
sql_frontend_extension 2
sr feuser register extension 2
sr_feuser_register_extension 2
terminal 2
Quick Filters