CVE-2014-3949
TYPO3 gridelements <2.0.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
References (4)
Scores
EPSS
0.0020
EPSS Percentile
42.0%
Details
CWE
CWE-79
Status
published
Products (32)
jo_hasenau/gridelements
< 1.5.0
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
jo_hasenau/gridelements
... and 22 more
Published
Jun 04, 2014
Tracked Since
Feb 18, 2026