VYPR

Vendor CVEs

TYPO3

All CVEs

614 total · sorted by risk
  • CVE-2021-43564HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the…

  • CVE-2021-38623HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.

  • CVE-2021-36786HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

  • CVE-2010-3668HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.

  • CVE-2021-36792HigAug 13, 2021
    risk 0.47cvss 7.2epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.

  • CVE-2019-19850HigDec 17, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed,…

  • CVE-2019-19848HigDec 17, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit…

  • CVE-2026-77145HigAug 25, 2026
    risk 0.46cvss —epss 0.00

    The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

  • CVE-2026-77144HigAug 25, 2026
    risk 0.46cvss —epss 0.00

    The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with…

  • CVE-2026-8727HigMay 19, 2026
    risk 0.46cvss —epss 0.00

    The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation…

  • CVE-2026-8726HigMay 19, 2026
    risk 0.46cvss —epss 0.00

    The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news…

  • CVE-2025-59022HigJan 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering…

  • CVE-2026-46721MedMay 19, 2026
    risk 0.45cvss —epss 0.00

    The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining…

  • CVE-2020-26216HigNov 17, 2020
    risk 0.45cvss 8.0epss 0.01

    TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities have been detected in Fluid: 1. TagBasedViewHelper allowed XSS through maliciously crafted additionalAttributes arrays by creating…

  • CVE-2026-0859HigJan 13, 2026
    risk 0.44cvss 7.8epss 0.00

    TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS…

  • CVE-2026-56095HigAug 25, 2026
    risk 0.43cvss —epss 0.00

    The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If…

  • CVE-2026-85400HigSep 8, 2026
    risk 0.42cvss —epss 0.00

    Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a…

  • CVE-2026-47346HigJun 9, 2026
    risk 0.42cvss —epss 0.00

    Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements,…

  • CVE-2026-11607HigJun 9, 2026
    risk 0.42cvss —epss 0.00

    Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements,…

  • CVE-2026-6553HigApr 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

  • CVE-2024-55921HigJan 14, 2025
    risk 0.42cvss 7.5epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2022-23503HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend…

  • CVE-2022-24980HigFeb 19, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF,…

  • CVE-2021-32669MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not properly encoded, the corresponding grid view…

  • CVE-2021-32668MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the components _QueryGenerator_ and…

  • CVE-2021-32667MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly encoded, corresponding page preview module…

  • CVE-2020-28917MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext…

  • CVE-2011-4904MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

  • CVE-2011-4902MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

  • CVE-2011-4901MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

  • CVE-2011-4900MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.5.4 allows Information Disclosure in the backend.

  • CVE-2011-4627MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

  • CVE-2010-3664MedNov 4, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

  • CVE-2019-11832HigMay 9, 2019
    risk 0.42cvss 7.5epss 0.05

    TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.

  • CVE-2026-77128MedAug 25, 2026
    risk 0.41cvss —epss 0.00

    The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this…

  • CVE-2026-56094MedAug 25, 2026
    risk 0.41cvss —epss 0.00

    The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3…

  • CVE-2026-19418HigAug 11, 2026
    risk 0.40cvss —epss 0.00

    The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a…

  • CVE-2026-47343HigJun 9, 2026
    risk 0.40cvss —epss 0.00

    Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0…

  • CVE-2025-47941HigMay 20, 2025
    risk 0.40cvss 7.2epss 0.00

    TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient…

  • CVE-2025-47940HigMay 20, 2025
    risk 0.40cvss 7.2epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and…

  • CVE-2024-22188HigMar 5, 2024
    risk 0.40cvss 7.2epss 0.02

    TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS,…

  • CVE-2021-36790MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.

  • CVE-2021-32768MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site…

  • CVE-2020-26227MedNov 23, 2020
    risk 0.40cvss 6.1epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers.…

  • CVE-2011-4903MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

  • CVE-2011-4626MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.

  • CVE-2010-3674MedNov 5, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.4.1 allows XSS in the frontend search box.

  • CVE-2010-3661MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

  • CVE-2019-12748MedJul 9, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.

  • CVE-2017-5963MedFeb 12, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An…

Page 2 of 13