typo3

346 tracked vulnerabilities.

CVE-2012-6144
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated SQL Injection
Jul 01, 2013
EPSS 0.01
CVE-2012-3531
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Cross-Site Scripting in Install Tool
Sep 05, 2012
EPSS 0.00
CVE-2012-3530
TYPO3 4.5.x < 4.5.19, 4.6.x < 4.6.12, 4.7.x < 4.7.4 - Cross-Site Scripting via HTML5 JavaScript Events
Sep 05, 2012
EPSS 0.01
CVE-2012-3529
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Authenticated Encryption Key Exposure
Sep 05, 2012
EPSS 0.00
CVE-2012-3528
TYPO3 4.5.0-4.5.18, 4.6.0-4.6.11, 4.7.0-4.7.3 - Authenticated Cross-Site Scripting
Sep 05, 2012
EPSS 0.01
CVE-2012-3527
TYPO3 4.5.0-4.5.18 - Authenticated Remote Code Execution via Unsafe Deserialization in Backend Help System
Sep 05, 2012
EPSS 0.02
CVE-2012-1608
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Cross-Site Scripting Bypass via Non-Printable Characters
Sep 04, 2012
EPSS 0.01
CVE-2012-1607
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Unauthenticated Database Name Exposure via CLI Script
Sep 04, 2012
EPSS 0.01
CVE-2012-1606
TYPO3 4.4.0-4.4.13 4.5.0-4.5.13 4.6.0-4.6.6 4.7 6.0 - Authenticated Cross-Site Scripting
Sep 04, 2012
EPSS 0.00
CVE-2012-1605
TYPO3 4.6.0-4.6.6, 4.7, 6.0 - Remote Code Execution via Extbase Framework Unserialization
Sep 04, 2012
EPSS 0.01
CVE-2012-2112
TYPO3 4.4.0-4.4.14, 4.5.0-4.5.14, 4.6.0-4.6.7, 4.7 - Cross-Site Scripting via Exception Handler
Aug 27, 2012
EPSS 0.01
CVE-2012-1086
TYPO3 aeurltool 0.1.0 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1085
TYPO3 beuserswitch <0.0.1 - Info Disclosure
Feb 14, 2012
EPSS 0.00
CVE-2012-1084
TYPO3 BE User Switch 0.0.1 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1083
TYPO3 Terminal < 0.3.2 - Cross-Site Request Forgery
Feb 14, 2012
EPSS 0.00
CVE-2012-1082
Terminal PHP Shell < 0.3.2 - Authenticated Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1080
skt_eurocalc 0.0.1 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1074
TYPO3 mm_whtppr <0.0.4 - SQL Injection
Feb 14, 2012
EPSS 0.00
CVE-2012-1073
TYPO3 toi_category < 0.6.0 - Cross-Site Scripting
Feb 14, 2012
EPSS 0.00
CVE-2012-1072
TYPO3 toi_category <0.6.0 - SQL Injection
Feb 14, 2012
EPSS 0.00
CVE-2011-3583 CRITICAL
Typo3 4.5.0-4.5.5 - SQL Injection via Prepared Statement Parameter Binding
Nov 26, 2019
CVSS 9.8
EPSS 0.00
CVE-2011-4904 MEDIUM
TYPO3 < 4.4.9 and 4.5.x < 4.5.4 - Unauthenticated Information Disclosure via ExtDirect Endpoint
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4903 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Cross-Site Scripting via RemoveXSS Function
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2011-4902 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Arbitrary File Deletion
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4901 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Unauthenticated Database Information Disclosure
Nov 06, 2019
CVSS 6.5
EPSS 0.00