TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5044
  • News 2456
  • Extensions 1918
  • Composer packages 345
  • Pages 306
  • Events 19
  1. Cross-Site Scripting in Form Manager Module

    Component Type: TYPO3 CMS Subcomponent: Form Framework (ext:form) Release Date: May 14, 2024 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.0.0-9.5.47, 10.0.0-10.4.44, 11.0.0-11.5.36,…

    Published: 14th May 2024 by Oliver Hader
  2. Cross-Site Scripting in Form Framework validation handling

    Component Type: TYPO3 CMS Subcomponent: Form Framework (ext:form) Release Date: December 17, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.29 and 9.0.0-9.5.11 and…

    Published: 17th December 2019 by Frank Nägler
  3. Cross-Site Scripting in Form Framework

    Component Type: TYPO3 CMS Subcomponent: Form Framework (ext:form) Release Date: June 14, 2022 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.46 ELTS, 9.0.0-9.5.34 ELTS,…

    Published: 14th June 2022 by Oliver Hader
  4. Cross-Site Scripting in Form Framework

    Component Type: TYPO3 CMS Subcomponent: Form Framework (ext:form) Release Date: March 16, 2021 Vulnerability Type: Cross-Site Scripting Affected Versions: 10.2.0-10.4.13, 11.0.0-11.1.0 Severity:…

    Published: 16th March 2021 by Oliver Hader
  5. Cross-Site Scripting in Form Framework

    Component Type: TYPO3 CMS Vulnerable subcomponent: Form Framework (ext:form) Release Date: January 22, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.5.0-8.7.22 and 9.0.0-9.5.3…

    Published: 22nd January 2019
  6. Cross-Site Scripting in Form Engine

    Component Type: TYPO3 CMS Subcomponent: Form Engine (ext:backend) Release Date: May 12, 2020 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.0.0-9.5.16, 10.0.0-10.4.1 Severity: Medium…

    Published: 12th May 2020 by Oliver Hader
  7. Cross-Site Scripting in Fluid ViewHelpers

    Component Type: TYPO3 CMS Vulnerable subcomponent: Fluid (ext:fluid) Release Date: January 22, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.22 and 9.0.0-9.5.3 Severity:…

    Published: 22nd January 2019
  8. Cross-Site Scripting in Fluid Engine

    Component Type: TYPO3 CMS Vulnerable subcomponent: Fluid Engine (package typo3fluid/fluid) Release Date: May 7, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.24 and…

    Published: 7th May 2019 by Oliver Hader
  9. Cross-Site Scripting in Flash component (ELTS)

    Release Date: January 22, 2019 (December 11, 2018 for ELTS) Vulnerability Type: Cross-Site Scripting Affected Versions: TYPO3 6.2.0 to 6.2.38 ELTS, TYPO3 7.0.0 to 7.1.0 Severity: Medium Suggested CVSS…

    Published: 22nd January 2019
  10. Cross-Site Scripting in Filelist Module

    Component Type: TYPO3 CMS Subcomponent: Filelist Module (ext:filelist) Release Date: December 17, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.29, 9.0.0-9.5.11 and…

    Published: 17th December 2019 by Andreas Fernandez
  11. Cross-Site Scripting in Extension "femanager" (femanager)

    Release Date: August 10, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "femanager" (femanager) Vulnerability Type: Cross-Site…

    Published: 10th August 2021 by Torben Hansen
  12. Cross-Site Scripting in Content Preview

    Component Type: TYPO3 CMS Subcomponent: Content Preview Renderer (ext:backend) Release Date: March 16, 2021 Vulnerability Type: Cross-Site Scripting Affected Versions: 7.0.0-7.6.50, 8.0.0-8.7.39,…

    Published: 16th March 2021 by Oliver Hader
  13. Cross-Site Scripting in Content Preview

    Component Type: TYPO3 CMS Subcomponent: Content Preview Renderer (ext:backend) Release Date: March 16, 2021 Vulnerability Type: Cross-Site Scripting Affected Versions: 10.0.0-10.4.1, 11.0.0-11.1.0…

    Published: 16th March 2021 by Oliver Hader
  14. Cross-Site Scripting in CKEditor4 WordCount Plugin

    Component Type: TYPO3 CMS Subcomponent: Rich Text Editor CKEditor4 (ext:rte_ckeditor) Release Date: July 25, 2023 Vulnerability Type: Cross-Site Scripting Affected Versions: 9.5.0-9.5.41,…

    Published: 25th July 2023 by Oliver Hader
  15. Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0

    Release Date: May 7, 2019 Component Type: Bootstrap CSS toolkit (bundled in TYPO3 core package, ext:core) Impact: Cross-Site Scripting, Known Vulnerability Affected Versions: all Bootstrap versions…

    Published: 7th May 2019 by Oliver Hader
  16. Cross-Site Scripting in Bootstrap CSS toolkit

    Component Type: TYPO3 CMS Vulnerable subcomponent: 3rd party library Bootstrap CSS toolkit Release Date: January 22, 2019 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.22 and…

    Published: 22nd January 2019
  17. Cross-Site Scripting in Backend Modal Component

    Component Type: TYPO3 CMS Vulnerable subcomponent: Backend modal component Release Date: December 11, 2018 Vulnerability Type: Cross-Site Scripting Affected Versions: 7.1.0-7.6.31, 8.5.0-8.7.20 and…

    Published: 11th December 2018 by Oliver Hader
  18. Cross-Site Scripting in Backend Grid View

    Component Type: TYPO3 CMS Subcomponent: Backend Grid View (ext:backend) Release Date: July 20, 2021 Vulnerability Type: Cross-Site Scripting Affected Versions: 8.0.0-8.7.40 ELTS, 9.0.0-9.5.27,…

    Published: 20th July 2021 by Oliver Hader
  19. Cross-Site Scripting in <f:asset.css> view helper

    Component Type: TYPO3 CMS Subcomponent: Fluid (ext:fluid) Release Date: September 13, 2022 Vulnerability Type: Cross-Site Scripting Affected Versions: 10.3.0-10.4.31, 11.0.0-11.5.15 Severity: Medium…

    Published: 13th September 2022 by Torben Hansen
  20. Cross-Site Scripting in 3rd party library Flowplayer

    Component Type: TYPO3 CMS Release Date: July 1, 2015 Vulnerable subcomponent: Frontend Media Rendering (ext:frontend, ext:mediace) Vulnerability Type: Cross-Site Scripting Affected Versions: Versions…

    Published: 1st July 2015 by Helmut Hummel
  21. Cross-Site Scripting in "SVG Sanitizer" (svg_sanitizer)

    Release Date: May 12, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: SVG Sanitizer (ext:svg_sanitizer) Vulnerability Type:…

    Published: 12th May 2020 by Oliver Hader
  22. Cross-Site Scripting and Remote Code Execution Vulnerability in TYPO3 Core

    Component Type: TYPO3 Core Vulnerability Types: Cross-Site Scripting, Remote Code Execution Overall Severity: Critical Release Date: July 30, 2013 Vulnerable subcomponent: Third Party Libraries used…

    Published: 30th July 2013 by Georg Ringer
  23. Cross-Site Scripting and Open Redirection vulnerability in extension phpMyAdmin (phpmyadmin)

    Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 4.10.3 and below Vulnerability Type: Cross-Site Scripting, Open…

    Published: 23rd May 2011 by Marcus Krause
  24. Cross-Site Scripting Vulnerability in TYPO3 Core

    Component Type: TYPO3 Core Affected Versions: 4.4.0 up to 4.4.14, 4.5.0 up to 4.5.14, 4.6.0 up to 4.6.7 and development releases of the 4.7 branch. Vulnerable subcomponent: Exception Handler…

    Published: 17th April 2012 by Helmut Hummel
  25. Cross-Site Request Forgery in extension "Typo3 Quixplorer" (t3quixplorer)

    Release Date: September 30, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.7.2 and below Vulnerability Type:…

    Published: 30th September 2015 by Nicole Cordes
    • «
    • ‹
    • ....
    • 171
    • 172
    • 173
    • 174
    • 175
    • 176
    • 177
    • 178
    • 179
    • 180
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy