TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5044
  • News 2456
  • Extensions 1918
  • Composer packages 345
  • Pages 306
  • Events 19
  1. Cross-Site Scripting in extension "Embedding schema.org vocabulary" (schema)

    Release Date: June 14, 2022 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Embedding schema.org vocabulary" (schema) Vulnerability…

    Published: 14th June 2022 by Torben Hansen
  2. Cross-Site Scripting in extension "CCDebug" (cc_debug)

    Release Date: July 7, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.0.0 and below Vulnerability Type:…

    Published: 7th July 2016 by Nicole Cordes
  3. Cross-Site Scripting in extension "Bootstrap Package" (bootstrap_package)

    Release Date: June 15, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 6.2.15 and below Vulnerability Type:…

    Published: 15th June 2016 by Nicole Cordes
  4. Cross-Site Scripting in extension "Bookdatabase" (extbookdatabase)

    Release Date: February 15, 2022 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Bookdatabase" (extbookdatabase) Vulnerability Type:…

    Published: 15th February 2022 by Torben Hansen
  5. Cross-Site Scripting in extension "Apache Solr for TYPO3" (solr)

    Release Date: March 03, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.8.3 and below, 3.0.0 to 3.0.1…

    Published: 3rd March 2016 by Nicole Cordes
  6. Cross-Site Scripting in extension "Aimeos shop and e-commerce framework" (aimeos)

    Release Date: Mar 16, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Aimeos shop and e-commerce framework" (aimeos)…

    Published: 16th March 2021 by Torben Hansen
  7. Cross-Site Scripting in extension "404 Page not found handling" (pagenotfoundhandling)

    Release Date: June 29, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.1.0 and below Vulnerability Type:…

    Published: 29th June 2015 by Nicole Cordes
  8. Cross-Site Scripting in extension "2 Clicks for External Media" (media2click)

    Release Date: April 27, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "2 Clicks for External Media" (media2click) Vulnerability…

    Published: 27th April 2021 by Torben Hansen
  9. Cross-Site Scripting in TYPO3 component Indexed Search

    Component Type: TYPO3 CMS Release Date: December 15, 2015 Vulnerable subcomponent: Indexed Search Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.15 Severity: Low…

    Published: 15th December 2015 by Helmut Hummel
  10. Cross-Site Scripting in TYPO3 component Extension Manager

    Component Type: TYPO3 CMS Release Date: December 15, 2015 Vulnerable subcomponent: Extension Manager Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.15, 7.0.0 to…

    Published: 15th December 2015 by Nicole Cordes
  11. Cross-Site Scripting in TYPO3 component CSS styled content

    Component Type: TYPO3 CMS Release Date: February 23, 2016 Vulnerable subcomponent: CSS styled content Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.18 and 7.6.0 to…

    Published: 23rd February 2016 by Nicole Cordes
  12. Cross-Site Scripting in TYPO3 component Backend

    Component Type: TYPO3 CMS Release Date: February 23, 2016 Vulnerable subcomponent: Backend Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.18 Severity: Low Suggested…

    Published: 23rd February 2016 by Nicole Cordes
  13. Cross-Site Scripting in TYPO3 Flow

    Component Type: TYPO3 Flow Affected Versions: 1.1.0, 2.0.0 and current development branch. Release Date: December 10, 2013 Vulnerability Type: Cross-Site Scripting Severity: Medium Suggested CVSS…

    Published: 10th December 2013 by Helmut Hummel
  14. Cross-Site Scripting in TYPO3 CMS Backend

    Component Type: TYPO3 CMS Release Date: September 5, 2017 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0 to 8.7.4 Severity: Low Suggested CVSS v2.0:…

    Published: 5th September 2017 by Oliver Hader
  15. Cross-Site Scripting in TYPO3 CMS

    Component Type: TYPO3 CMS Release Date: February 28, 2017 Vulnerability Type: Cross-Site Scripting Affected Versions: 7.6.0 to 7.6.15 and 8.0.0 to 8.6.0 Severity: Low Suggested CVSS v2.0:…

    Published: 28th February 2017 by Nicole Cordes
  16. Cross-Site Scripting in TYPO3 Backend

    Component Type: TYPO3 CMS Release Date: September 13, 2016 Vulnerability Type: Cross-Site Scripting Affected Versions: 6.2.0 to 6.2.26, 7.6.0 to 7.6.10 and 8.0.0 to 8.3.0 Severity: Low Suggested CVSS…

    Published: 13th September 2016 by Georg Ringer
  17. Cross-Site Scripting in TYPO3 Backend

    Component Type: TYPO3 CMS Release Date: July 19, 2016 Vulnerable subcomponent: Backend Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.25, 7.6.0 to 7.6.9 and 8.0.0 to…

    Published: 19th July 2016 by Nicole Cordes
  18. Cross-Site Scripting in TYPO3 Backend

    Component Type: TYPO3 CMS Release Date: April 12, 2016 Vulnerable subcomponent: Backend Vulnerability Type: Cross-Site Scripting Affected Versions: Versions 6.2.0 to 6.2.19, 7.6.0 to 7.6.4 and 8.0.0…

    Published: 12th April 2016 by Helmut Hummel
  19. Cross-Site Scripting in ShowImageController

    Component Type: TYPO3 CMS Subcomponent: Frontend Rendering (ext:frontend) Release Date: May 14, 2024 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.0.0-9.5.47, 10.0.0-10.4.44,…

    Published: 14th May 2024 by Oliver Hader
  20. Cross-Site Scripting in Page Preview

    Component Type: TYPO3 CMS Subcomponent: Page Preview (ext:viewpage) Release Date: July 20, 2021 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.0.0-9.5.27, 10.0.0-10.4.17, 11.0.0-11.3.0…

    Published: 20th July 2021 by Oliver Hader
  21. Cross-Site Scripting in Link Handling & File List

    Component Type: TYPO3 CMS Release Date: July 1, 2015 Vulnerable subcomponent: Link Handling (ext:frontend), Filelist Module (ext:filelist, ext:core) Vulnerability Type: Cross-Site Scripting Affected…

    Published: 1st July 2015 by Helmut Hummel
  22. Cross-Site Scripting in Link Handling

    Component Type: TYPO3 CMS Subcomponent: Link Handling (ext:frontend) Release Date: May 12, 2020 Vulnerability Type: Information Disclosure Affected Versions: 9.5.12-9.5.16, 10.2.0-10.4.1 Severity:…

    Published: 12th May 2020 by Oliver Hader
  23. Cross-Site Scripting in Link Handling

    Component Type: TYPO3 CMS Subcomponent: Link Handling (ext:core, ext:frontend) Release Date: December 17, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.29 and 9.0.0-9.5.11…

    Published: 17th December 2019 by Frank Nägler
  24. Cross-Site Scripting in Language Pack Handling

    Component Type: TYPO3 CMS Vulnerable subcomponent: Language Pack Handling (ext:install) Release Date: January 22, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.2.0-9.5.3 Severity:…

    Published: 22nd January 2019
  25. Cross-Site Scripting in Frontend Login Mailer

    Component Type: TYPO3 CMS Subcomponent: Frontend Login Mailer (ext:felogin) Release Date: June 14, 2022 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.0.0-9.5.34 ELTS, 10.0.0-10.4.28,…

    Published: 14th June 2022 by Oliver Hader
    • «
    • ‹
    • ....
    • 170
    • 171
    • 172
    • 173
    • 174
    • 175
    • 176
    • 177
    • 178
    • 179
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy