Security Advisories
All Advisories
TYPO3-EXT-SA-2022-016: Insufficient Session Expiration after Password Change in extension "Change password for frontend users" (fe_change_pwd)
It has been discovered that the extension "Change password for frontend users" (fe_change_pwd) is susceptible to insufficient session expiration.
TYPO3-CORE-SA-2022-017: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure.
TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
It has been discovered that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset
It has been discovered that TYPO3 CMS is susceptible to insufficient session expiration.
TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login
It has been discovered that TYPO3 CMS is susceptible to weak authentication.
TYPO3-CORE-SA-2022-012: Denial of Service in Page Error Handling
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-EXT-SA-2022-015: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-CORE-SA-2022-011: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-010: Cross-Site Scripting in <f:asset.css> view helper
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-009: Stored Cross-Site Scripting via FileDumpController
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-008: Missing check for expiration time of password reset token for backend users
It has been discovered that TYPO3 CMS is vulnerable to broken access control.
TYPO3-CORE-SA-2022-007: User Enumeration via Response Timing
It has been discovered that TYPO3 CMS is vulnerable to information disclosure.
TYPO3-CORE-SA-2022-006: Denial of Service in Page Error Handling
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-EXT-SA-2022-014: SQL Injection in extension "LUX - TYPO3 Marketing Automation" (lux)
It has been discovered that the extension "LUX - TYPO3 Marketing Automation" (lux) is susceptible to SQL Injection.
TYPO3-CORE-SA-2022-005: Insufficient Session Expiration in Admin Tool
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2022-004: Cross-Site Scripting in Frontend Login Mailer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-003: Cross-Site Scripting in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-002: Information Disclosure via Exception Handling/Logger
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2022-001: Information Disclosure via Export Module
It has been discovered that TYPO3 CMS is susceptible to information disclosure.