typo3/cms
Packagist116 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cmspage 2 of 3
- CVE-2014-9509NONECVSS 0.0EG 0.0✓ Fixed in 6.1.132015-01-04
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly …
- CVE-2015-5956NONECVSS 0.0EG 0.02015-09-16
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as dem…
- CVE-2015-8755MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.6.12016-01-08
vulnerable: 7.0.0 ... 7.6.0 (10 versions)
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
- CVE-2015-8756MEDIUMCVSS 5.4EG 5.4✓ Fixed in 6.2.162016-01-08
vulnerable: 6.2.0 ... 6.2.9 (17 versions)
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vec…
- CVE-2015-8759MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.6.12016-01-08
vulnerable: 7.0.0 ... 7.6.0 (10 versions)
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.
- CVE-2015-8760MEDIUMCVSS 6.1EG 6.1✓ Fixed in 6.2.162016-01-08
vulnerable: 6.2.0 ... 6.2.9 (17 versions)
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."
- CVE-2016-4056MEDIUMCVSS 6.1EG 6.1✓ Fixed in 6.2.192017-01-23
vulnerable: 6.2.0 ... 6.2.9 (20 versions)
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
- CVE-2017-14251HIGHCVSS 8.8EG 8.8✓ Fixed in 8.7.52017-09-11
vulnerable: 8.0.0 ... v8.7.4 (20 versions)
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and …
- CVE-2017-6370MEDIUMCVSS 5.3EG 5.32017-03-17
vulnerable: 7.6.15
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fie…
- CVE-2018-14041MEDIUMCVSS 6.1EG 6.1✓ Fixed in 9.5.42018-07-13
vulnerable: v9.0.0 ... v9.5.3 (13 versions)
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
- CVE-2018-17960MEDIUMCVSS 6.1EG 6.1✓ Fixed in 9.5.22018-11-14
vulnerable: v9.0.0 ... v9.5.1 (11 versions)
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
- CVE-2018-6905MEDIUMCVSS 4.8EG 4.8✓ Fixed in 9.2.02018-04-08
vulnerable: 6.2.0 ... v9.1.0 (125 versions)
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
- CVE-2019-10912HIGHCVSS 7.1EG 7.1✓ Fixed in 9.5.82019-05-16
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that t…
- CVE-2019-11832HIGHCVSS 7.5EG 7.5✓ Fixed in 9.5.62019-05-09
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
- CVE-2019-12747HIGHCVSS 8.8EG 8.8✓ Fixed in 9.5.82019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
- CVE-2019-12748MEDIUMCVSS 6.1EG 6.1✓ Fixed in 9.5.82019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
- CVE-2019-19848HIGHCVSS 7.2EG 7.2✓ Fixed in 9.5.122019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privil…
- CVE-2019-19849HIGHCVSS 8.8EG 8.8✓ Fixed in 9.5.122019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires h…
- CVE-2019-19850HIGHCVSS 7.2EG 7.2✓ Fixed in 10.2.22019-12-17
vulnerable: v10.0.0, v10.1.0, v10.2.0, v10.2.1
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the …
- CVE-2020-11063LOWCVSS 3.7EG 3.7✓ Fixed in 10.4.22020-05-13
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2020-11064MEDIUMCVSS 5.4EG 5.4✓ Fixed in 9.5.172020-05-13
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to …
- CVE-2020-11065MEDIUMCVSS 5.4EG 5.4✓ Fixed in 9.5.172020-05-13
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; …
- CVE-2020-11066HIGHCVSS 8.7EG 8.7✓ Fixed in 9.5.172020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object …
- CVE-2020-11067HIGHCVSS 8.8EG 8.8✓ Fixed in 9.5.172020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, thi…
- CVE-2020-11069HIGHCVSS 8.0EG 8.0✓ Fixed in 9.5.172020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malic…
- CVE-2020-15098HIGHCVSS 8.8EG 8.8✓ Fixed in 9.5.202020-07-29
vulnerable: v9.0.0 ... v9.5.9 (29 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This al…
- CVE-2020-15099HIGHCVSS 8.1EG 8.1✓ Fixed in 9.5.202020-07-29
vulnerable: v9.0.0 ... v9.5.9 (29 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - eit…
- CVE-2020-15241MEDIUMCVSS 4.7EG 4.7✓ Fixed in 9.5.62020-10-08
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? …
- CVE-2020-26227MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.7.382020-11-23
vulnerable: 8.7.0 ... v8.7.9 (33 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data …
- CVE-2020-26228HIGHCVSS 8.1EG 8.1✓ Fixed in 8.7.382020-11-23
vulnerable: 8.7.0 ... v8.7.9 (33 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vuln…
- CVE-2020-26229LOWCVSS 3.7EG 3.7✓ Fixed in 10.4.102020-11-23
vulnerable: v10.0.0 ... v10.4.9 (16 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical …
- CVE-2020-8091MEDIUMCVSS 6.1EG 6.1✓ Fixed in 6.2.392020-01-27
vulnerable: 6.2.0 ... 6.2.9 (33 versions)
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.
- CVE-2021-21338MEDIUMCVSS 4.7EG 4.7✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers …
- CVE-2021-21339MEDIUMCVSS 5.9EG 5.9✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic ha…
- CVE-2021-21340MEDIUMCVSS 5.4EG 5.4✓ Fixed in 11.1.12021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content get…
- CVE-2021-21355HIGHCVSS 8.6EG 8.6✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary …
- CVE-2021-21357HIGHCVSS 8.3EG 8.3✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data …
- CVE-2021-21358MEDIUMCVSS 5.4EG 5.4✓ Fixed in 11.1.12021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid bac…
- CVE-2021-21359MEDIUMCVSS 5.9EG 5.9✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to b…
- CVE-2021-21370MEDIUMCVSS 5.4EG 5.4✓ Fixed in 9.5.252021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their…
- CVE-2021-32667MEDIUMCVSS 6.4EG 6.4✓ Fixed in 9.5.282021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly enc…
- CVE-2021-32668MEDIUMCVSS 6.4EG 6.4✓ Fixed in 9.5.282021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the …
- CVE-2021-32669MEDIUMCVSS 6.4EG 6.4✓ Fixed in 9.5.282021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not proper…
- CVE-2021-32767MEDIUMCVSS 5.3EG 5.3✓ Fixed in 9.5.282021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log lev…
- CVE-2021-32768MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.6.532021-08-10
vulnerable: 7.0.0 ... v7.6.32 (42 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website front…
- CVE-2021-41113HIGHCVSS 8.8EG 8.8✓ Fixed in 11.5.02021-10-05
vulnerable: v11.2.0 ... v11.4.0 (6 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature that allows users to create and share deep links in the backend user interface is vulnerable …
- CVE-2021-41114MEDIUMCVSS 4.8EG 4.8✓ Fixed in 11.5.02021-10-05
vulnerable: v11.0.0 ... v11.4.0 (9 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP Host header. TYPO3 uses the HTTP Host …
- CVE-2022-23499MEDIUMCVSS 6.1EG 6.1✓ Fixed in 12.1.12022-12-13
vulnerable: v12.0.0, v12.1.0
HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1, malicious markup used in a sequence with special HTML CDATA sections cannot …
- CVE-2022-23500MEDIUMCVSS 5.9EG 5.9✓ Fixed in 11.5.202022-12-14
vulnerable: v11.0.0 ... v11.5.9 (29 versions)
TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve c…
- CVE-2022-23501MEDIUMCVSS 5.9EG 5.9✓ Fixed in 12.1.12022-12-14
vulnerable: v12.0.0, v12.1.0
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in d…
Check whether typo3/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms CVEs against the assets you own.
Start Free Scan →