VYPR

Vendor CVEs

TYPO3

All CVEs

614 total · sorted by risk
  • CVE-2017-5962MedFeb 12, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker…

  • CVE-2016-4056MedJan 23, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.

  • CVE-2015-8757MedJan 8, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.

  • CVE-2026-77139MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or…

  • CVE-2026-77133MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.

  • CVE-2026-77127MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses…

  • CVE-2026-49742HigJun 9, 2026
    risk 0.39cvss —epss 0.00

    Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such…

  • CVE-2024-25121HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage…

  • CVE-2026-46724MedMay 19, 2026
    risk 0.38cvss —epss 0.00

    The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.

  • CVE-2026-46723MedMay 19, 2026
    risk 0.38cvss —epss 0.00

    The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.

  • CVE-2026-46722MedMay 19, 2026
    risk 0.38cvss —epss 0.00

    The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search…

  • CVE-2021-21359MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.02

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another…

  • CVE-2021-21339MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability…

  • CVE-2023-50460MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.

  • CVE-2025-59021MedJan 13, 2026
    risk 0.35cvss 6.4epss 0.00

    Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects…

  • CVE-2025-59020MedJan 13, 2026
    risk 0.35cvss 6.5epss 0.00

    By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write…

  • CVE-2025-59018MedSep 9, 2025
    risk 0.35cvss 6.5epss 0.00

    Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information…

  • CVE-2025-59015MedSep 9, 2025
    risk 0.35cvss 6.5epss 0.00

    A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

  • CVE-2025-7900MedJul 22, 2025
    risk 0.35cvss 6.5epss 0.00

    The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0

  • CVE-2022-36108MedSep 13, 2022
    risk 0.35cvss 6.5epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or…

  • CVE-2022-36107MedSep 13, 2022
    risk 0.35cvss 6.5epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid…

  • CVE-2022-29602MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS.

  • CVE-2022-33155MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.

  • CVE-2022-24979MedFeb 19, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct…

  • CVE-2021-43561MedNov 10, 2021
    risk 0.35cvss 5.4epss 0.01

    An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

  • CVE-2021-36791MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.

  • CVE-2021-21370MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the…

  • CVE-2021-21358MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the…

  • CVE-2021-21340MedMar 23, 2021
    risk 0.35cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A valid backend user…

  • CVE-2020-15516MedJul 7, 2020
    risk 0.35cvss 5.4epss 0.00

    The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.

  • CVE-2020-15514MedJul 7, 2020
    risk 0.35cvss 5.4epss 0.01

    The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.

  • CVE-2020-15513MedJul 7, 2020
    risk 0.35cvss 5.3epss 0.01

    The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.

  • CVE-2020-11065MedMay 13, 2020
    risk 0.35cvss 5.4epss 0.01

    In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; properties being assigned as HTML…

  • CVE-2020-11064MedMay 13, 2020
    risk 0.35cvss 5.4epss 0.01

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend…

  • CVE-2020-11070MedMay 13, 2020
    risk 0.35cvss 5.4epss 0.01

    The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads…

  • CVE-2011-4632MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.

  • CVE-2011-4631MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.

  • CVE-2011-4630MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links wizard.

  • CVE-2011-4629MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel.

  • CVE-2010-3671MedNov 5, 2019
    risk 0.35cvss 6.5epss 0.02

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

  • CVE-2010-3669MedNov 4, 2019
    risk 0.35cvss 5.4epss 0.01

    TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

  • CVE-2010-3665MedNov 4, 2019
    risk 0.35cvss 5.4epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.

  • CVE-2010-3660MedNov 1, 2019
    risk 0.35cvss 5.4epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.

  • CVE-2010-3659MedOct 20, 2017
    risk 0.35cvss 5.4epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension…

  • CVE-2017-6370MedMar 17, 2017
    risk 0.35cvss 5.3epss 0.01

    TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

  • CVE-2015-8758MedJan 8, 2016
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2015-8755MedJan 8, 2016
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2026-77131MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

  • CVE-2026-77130MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

  • CVE-2026-56093MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without…

Page 3 of 13