Security Advisories
All Advisories
TYPO3-EXT-SA-2019-002: Multiple vulnerabilities in extension "typo3_forum" (typo3_forum)
It has been discovered that the extension "typo3_forum" (typo3_forum) is susceptible to Broken Access Control and Improper Filesystem Permissions.
TYPO3-CORE-SA-2019-001: Information Disclosure of Installed Extensions
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2019-001: Multiple vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to Cross-Site Scripting, CSRF, File Inclusion and Remote Code…
TYPO3-PSA-2019-001: Possible Arbitrary Code Execution in CommandUtility API
It has been discovered that TYPO3 CMS can be vulnerable to arbitrary code execution.
TYPO3-PSA-2019-002: Username and Email Address Enumeration
It has been discovered, that usernames and email addresses may be enumerated with brute-force techniques, when using validators in order to ensure a…
TYPO3-PSA-2019-003: Cross-Site Scripting in Flash component (ELTS)
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2018-012: Denial of Service in Frontend Record Registration
It has been discovered, that TYPO3 CMS is vulnerable to denial of service.
TYPO3-CORE-SA-2018-011: Denial of Service in Online Media Asset Handling
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2018-010: Information Disclosure in Install Tool
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2018-009: Security Misconfiguration in Install Tool Cookie
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2018-008: Cross-Site Scripting in Frontend User Login
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2018-007: Cross-Site Scripting in Backend Modal Component
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2018-006: Cross-Site Scripting in Online Media Asset Rendering
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2018-005: Cross-Site Scripting in CKEditor
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-PSA-2018-002: Web Resource Restrictions
It has been discovered that development related information can be retrieved by regular HTTP GET requests on NGINX web server environments missing…
TYPO3-EXT-SA-2018-010: Cross-Site Scripting in extension "libconnect" (libconnect)
It has been discovered that the extension "libconnect" (libconnect) is susceptible to Cross-Site Scripting.
TYPO3-PSA-2018-001: By-passing Protection of PharStreamWrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in PharStreamWrapper component.
TYPO3-EXT-SA-2018-009: Information Disclosure in extension "TemplaVoilà! Plus" (templavoilaplus)
It has been discovered that the extension "TemplaVoilà! Plus" (templavoilaplus) is susceptible to Information Disclosure.
TYPO3-EXT-SA-2018-008: Cross-Site Scripting in extension "Frontend Treeview" (mh_treeview)
It has been discovered that the extension "Frontend Treeview" (mh_treeview) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2018-007: Environment Variable Injection in extension "Amazon Web Services SDK " (aws_sdk)
It has been discovered that the extension "Amazon Web Services SDK " (aws_sdk) is susceptible to Environment Variable Injection.