CVE-2009-4963

Typo3 Commerce Extension < 0.9.8 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0021
EPSS Percentile 43.1%

Classification

CWE
CWE-79
Status published

Affected Products (9)

typo3/commerce_extension < 0.9.8
typo3/commerce_extension
typo3/commerce_extension
typo3/commerce_extension
typo3/commerce_extension
typo3/commerce_extension
typo3/commerce_extension
commerceteam/commerce < 0.9.9Packagist
n/a/n/a

Timeline

Published Jul 28, 2010
Tracked Since Feb 18, 2026