typo3

346 tracked vulnerabilities.

CVE-2011-4900 MEDIUM
TYPO3 < 4.5.4 - Information Disclosure in Backend
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4632 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Cross-Site Scripting via Flash Message
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2011-4631 MEDIUM
TYPO3 < 4.3.12 - Cross-Site Scripting in System Extension Recycler
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2011-4630 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Cross-Site Scripting via Browse Links Wizard
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2011-4629 MEDIUM
TYPO3 < 4.3.12 - Cross-Site Scripting via Admin Panel
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2011-4628 CRITICAL
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Authentication Bypass
Nov 06, 2019
CVSS 9.8
EPSS 0.01
CVE-2011-4627 MEDIUM
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Information Disclosure
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2011-4626 MEDIUM
TYPO3 < 4.3.12 - Cross-Site Scripting via JSwindow Property in Typolink Function
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2011-4614
TYPO3 4.5.x-4.5.9 4.6.x-4.6.2 4.7 - Remote Code Execution via BACK_PATH Parameter
Feb 18, 2012
EPSS 0.02
CVE-2010-3674 MEDIUM
TYPO3 < 4.4.1 - Cross-Site Scripting in Frontend Search Box
Nov 05, 2019
CVSS 6.1
EPSS 0.00
CVE-2010-3673 MEDIUM
TYPO3 < 4.2.13 - Information Disclosure in HTML Mailing API
Nov 05, 2019
CVSS 5.3
EPSS 0.00
CVE-2010-3672 MEDIUM
TYPO3 < 4.3.4 and 4.4.x < 4.4.1 - Cross-Site Scripting in Extbase Textarea View Helper
Nov 05, 2019
CVSS 6.1
EPSS 0.00
CVE-2010-3671 MEDIUM
TYPO3 <4.1.14, <4.2.13, <4.3.4, <4.4.1 - Info Disclosure
Nov 05, 2019
CVSS 6.5
EPSS 0.01
CVE-2010-3670 MEDIUM
TYPO3 < 4.3.4 and 4.4.x < 4.4.1 - Insecure Randomness in Password Reset Hash Generation
Nov 05, 2019
CVSS 4.8
EPSS 0.00
CVE-2010-3669 MEDIUM
TYPO3 4.2.0-4.2.12 - Cross-Site Scripting and Open Redirect in Frontend Login Box
Nov 04, 2019
CVSS 5.4
EPSS 0.00
CVE-2010-3668 HIGH
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Header Injection via Secure Download Feature
Nov 04, 2019
CVSS 7.5
EPSS 0.00
CVE-2010-3667 MEDIUM
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Spam Abuse via Native Form Content Element
Nov 04, 2019
CVSS 5.3
EPSS 0.00
CVE-2010-3666 MEDIUM
TYPO3 <4.1.14, <4.2.13, <4.3.4, <4.4.1 - Info Disclosure
Nov 04, 2019
CVSS 5.3
EPSS 0.00
CVE-2010-3665 MEDIUM
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Cross-Site Scripting in Extension Manager
Nov 04, 2019
CVSS 5.4
EPSS 0.00
CVE-2010-3664 MEDIUM
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Information Disclosure in Backend
Nov 04, 2019
CVSS 6.5
EPSS 0.01
CVE-2010-3663 HIGH
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Remote Code Execution
Nov 04, 2019
CVSS 8.8
EPSS 0.03
CVE-2010-3662 HIGH
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - SQL Injection
Nov 04, 2019
CVSS 8.8
EPSS 0.00
CVE-2010-3661 MEDIUM
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Open Redirect in Backend
Nov 01, 2019
CVSS 6.1
EPSS 0.00
CVE-2010-3660 MEDIUM
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - Cross-Site Scripting in Backend
Nov 01, 2019
CVSS 5.4
EPSS 0.00
CVE-2010-3659 MEDIUM
TYPO3 CMS 4.1.0-4.1.13, 4.2.0-4.2.12, 4.3.0-4.3.3, 4.4.0 - Authenticated Cross-Site Scripting
Oct 20, 2017
CVSS 5.4
EPSS 0.00