Security Advisories
All Advisories
TYPO3-CORE-SA-2025-008: Cross-Site Request Forgery in Indexed Search Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-007: Cross-Site Request Forgery in Form Framework Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-006: Cross-Site Request Forgery in Extension Manager Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-005: Cross-Site Request Forgery in Dashboard Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-004: Cross-Site Request Forgery in Backend User Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-003: Cross-Site Request Forgery in Log Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-002: Potential Open Redirect via Parsing Differences
It has been discovered that TYPO3 CMS is susceptible to open redirect.
TYPO3-CORE-SA-2025-001: Information Disclosure via Exception Handling/Logger
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2024-012: Information Disclosure in TYPO3 Page Tree
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2024-011: Denial of Service in TYPO3 Bookmark Toolbar
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
TYPO3-EXT-SA-2024-006: Multiple vulnerabilities in "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference and Broken Access Control.
TYPO3-EXT-SA-2024-005: Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos)
It has been discovered that the extension "Aimeos shop and e-commerce framework" (aimeos) is susceptible to Remote Code Execution and Insecure Direct…
TYPO3-EXT-SA-2024-004: Broken Access Control in "Integration of Friendly Captcha" (friendlycaptcha_official)
It has been discovered that the extension "Integration of Friendly Captcha" (friendlycaptcha_official) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2024-003: Multiple vulnerabilities in "Events 2" (events2)
It has been discovered that the extension "Events 2" (events2) is susceptible to Cache Poisoning, Insecure Direct Object Reference and SQL wildcard…
TYPO3-CORE-SA-2024-010: Uncontrolled Resource Consumption in ShowImageController
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-CORE-SA-2024-009: Cross-Site Scripting in ShowImageController
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2024-008: Cross-Site Scripting in Form Manager Module
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2024-007: HTML Injection in History Module
It has been discovered that TYPO3 CMS is vulnerable to HTML injection.
TYPO3-EXT-SA-2024-002: Authentication Bypass in "OpenID Connect Authentication" (oidc)
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Authentication Bypass.