Security Advisories
All Advisories
TYPO3-EXT-SA-2023-010: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2023-009: Insecure Direct Object Reference in extension "Content Consent" (content_consent)
It has been discovered that the extension "Content Consent" (content_consent) is susceptible to Insecure Direct Object Reference.
TYPO3-CORE-SA-2023-007: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2023-006: Weak Authentication in Session Handling
It has been discovered that TYPO3 CMS is susceptible to weak authentication.
TYPO3-CORE-SA-2023-005: Information Disclosure in Install Tool
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2023-008: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2023-007: Broken Access Control in extension "hCaptcha for EXT:form" (hcaptcha)
It has been discovered that the extension "hCaptcha for EXT:form" (hcaptcha) is susceptible to Broken Access Control.
TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2023-002: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2023-006: Multiple vulnerabilities in extension "Canto Extension" (canto_extension)
It has been discovered that the extension "Canto Extension" (canto_extension) is susceptible to Server Side Request Forgery and Remote Code Execution.
TYPO3-EXT-SA-2023-005: SQL Injection in extension "ipandlanguageredirect" (ipandlanguageredirect)
It has been discovered that the extension "ipandlanguageredirect" (ipandlanguageredirect) is susceptible to SQL Injection.
TYPO3-EXT-SA-2023-004: Cross-Site Scripting in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2023-003: Cross-Site Scripting in extension "Fluid Components" (fluid_components)
It has been discovered that the extension "Fluid Components" (fluid_components) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2023-002: Persisted Cross-Site Scripting in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) is susceptible to Cross-Site Scripting.
TYPO3-CORE-SA-2023-001: Persisted Cross-Site Scripting in Frontend Rendering
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement
The TYPO3 Security Team pre-announces an important security release.
TYPO3-EXT-SA-2023-001: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
It has been discovered that the extension "Master-Quiz" (fp_masterquiz) is susceptible to Information Disclosure and Broken Access Control.
TYPO3-EXT-SA-2022-017: Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
It has been discovered that the extension "Newsletter subscriber management" (fp_newsletter) is susceptible to Information Disclosure and Broken…