VYPR

TYPO3 extension

by TYPO3

CVEs (4)

  • CVE-2026-46725CriMay 19, 2026
    risk 0.60cvss —epss 0.02

    The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3…

  • CVE-2020-15515HigJul 7, 2020
    risk 0.57cvss 8.8epss 0.02

    The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.

  • CVE-2026-77135HigAug 25, 2026
    risk 0.53cvss —epss 0.00

    The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and…

  • CVE-2020-15513MedJul 7, 2020
    risk 0.35cvss 5.3epss 0.01

    The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.