VYPR

Vendor CVEs

TYPO3

All CVEs

572 total · sorted by risk
  • CVE-2022-23503HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend…

  • CVE-2021-32669MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not properly encoded, the corresponding grid view…

  • CVE-2021-32668MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the components _QueryGenerator_ and…

  • CVE-2021-32667MedJul 20, 2021
    risk 0.42cvss 6.4epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly encoded, corresponding page preview module…

  • CVE-2020-28917MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext…

  • CVE-2011-4904MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

  • CVE-2011-4902MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

  • CVE-2011-4901MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

  • CVE-2011-4900MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.5.4 allows Information Disclosure in the backend.

  • CVE-2011-4627MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

  • CVE-2010-3664MedNov 4, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

  • CVE-2019-11832HigMay 9, 2019
    risk 0.42cvss 7.5epss 0.04

    TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.

  • CVE-2026-19418HigAug 11, 2026
    risk 0.40cvss epss 0.00

    The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a…

  • CVE-2026-47343HigJun 9, 2026
    risk 0.40cvss epss 0.00

    Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0…

  • CVE-2025-47941HigMay 20, 2025
    risk 0.40cvss 7.2epss 0.00

    TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient…

  • CVE-2025-47940HigMay 20, 2025
    risk 0.40cvss 7.2epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and…

  • CVE-2024-22188HigMar 5, 2024
    risk 0.40cvss 7.2epss 0.02

    TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS,…

  • CVE-2021-36790MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.

  • CVE-2021-32768MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site…

  • CVE-2020-26227MedNov 23, 2020
    risk 0.40cvss 6.1epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers.…

  • CVE-2011-4903MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

  • CVE-2011-4626MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.

  • CVE-2010-3674MedNov 5, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.4.1 allows XSS in the frontend search box.

  • CVE-2010-3661MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

  • CVE-2019-12748MedJul 9, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.

  • CVE-2017-5963MedFeb 12, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An…

  • CVE-2017-5962MedFeb 12, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker…

  • CVE-2016-4056MedJan 23, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.

  • CVE-2015-8757MedJan 8, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.

  • CVE-2026-49742HigJun 9, 2026
    risk 0.39cvss epss 0.00

    Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such…

  • CVE-2024-25121HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage…

  • CVE-2026-46724MedMay 19, 2026
    risk 0.38cvss epss 0.00

    The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.

  • CVE-2026-46723MedMay 19, 2026
    risk 0.38cvss epss 0.00

    The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.

  • CVE-2026-46722MedMay 19, 2026
    risk 0.38cvss epss 0.00

    The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search…

  • CVE-2021-21359MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.02

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another…

  • CVE-2021-21339MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability…

  • CVE-2025-59021MedJan 13, 2026
    risk 0.35cvss 6.4epss 0.00

    Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects…

  • CVE-2025-59020MedJan 13, 2026
    risk 0.35cvss 6.5epss 0.00

    By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write…

  • CVE-2025-59018MedSep 9, 2025
    risk 0.35cvss 6.5epss 0.00

    Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information…

  • CVE-2025-59015MedSep 9, 2025
    risk 0.35cvss 6.5epss 0.00

    A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

  • CVE-2025-7900MedJul 22, 2025
    risk 0.35cvss 6.5epss 0.00

    The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0

  • CVE-2022-36108MedSep 13, 2022
    risk 0.35cvss 6.5epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or…

  • CVE-2022-36107MedSep 13, 2022
    risk 0.35cvss 6.5epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid…

  • CVE-2022-29602MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS.

  • CVE-2022-24979MedFeb 19, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct…

  • CVE-2021-36791MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.

  • CVE-2021-21370MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the…

  • CVE-2021-21358MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the…

  • CVE-2021-21340MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A valid backend user…

  • CVE-2020-15516MedJul 7, 2020
    risk 0.35cvss 5.4epss 0.00

    The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.

Page 2 of 12