in2code/femanager
Packagist9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting in2code/femanagerpage 1 of 1
- CVE-2014-6292MEDIUMCVSS v2 6.4EG 6.4fixed in 1.0.92014-10-03
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.
- CVE-2021-36787MEDIUMCVSS 5.4EG 5.4fixed in 5.5.1 or 6.3.1, by version range2021-08-13
vulnerable: 6.0.0 ... 6.3.0 (8 versions)
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
- CVE-2022-44543MEDIUMCVSS 5.3EG 5.3fixed in 7.0.1, 6.3.3 or 5.5.2, by version range2023-12-12
vulnerable: 2.5.0 ... 5.5.1 (37 versions)
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inLis…
- CVE-2023-25013HIGHCVSS 8.6EG 8.6fixed in 5.5.3, 6.3.4 or 7.1.0, by version range2023-02-02
vulnerable: 7.0.0, 7.0.1
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
- CVE-2023-25014HIGHCVSS 8.6EG 8.6fixed in 5.5.3, 6.3.4 or 7.1.0, by version range2023-02-02
vulnerable: 7.0.0, 7.0.1
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
- CVE-2023-45023MEDIUMCVSS 4.2EG 4.2fixed in 7.2.22026-09-14
vulnerable: 7.0.0 ... 7.2.1 (6 versions)
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
- CVE-2023-50459MEDIUMCVSS 5.4EG 5.4fixed in 7.2.32026-09-14
vulnerable: 7.0.0 ... 7.2.2 (7 versions)
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users …
- CVE-2025-48202MEDIUMCVSS 5.3EG 5.3fixed in 8.2.2, 7.4.2, 6.4.1 or 5.5.5, by version range2025-05-21
vulnerable: 5.5.0, 5.5.1, 5.5.2, 5.5.3, 5.5.4
The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
- CVE-2025-7900MEDIUMCVSS 6.5EG 6.5fixed in 6.4.2, 7.5.3 or 8.3.1, by version range2025-07-22
vulnerable: 8.0.0 ... 8.3.0 (7 versions)
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Check whether in2code/femanager is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for in2code/femanager CVEs against the assets you own.
Book a Demo →