typo3/cms-core
Packagist99 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cms-corepage 1 of 2
- CVE-2008-2717MEDIUMCVSS v2 6.5EG 6.5fixed in 4.0.9, 4.1.7 or 4.2.1, by version range2008-06-16
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such …
- CVE-2009-3633MEDIUMCVSS v2 4.3EG 4.3fixed in 4.1.13, 4.2.10 or 4.3beta2, by version range2009-11-02
Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or…
- CVE-2010-3673MEDIUMCVSS 5.3EG 5.3fixed in 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-05
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
- CVE-2010-5104MEDIUMCVSS v2 4.3EG 4.3fixed in 4.2.16, 4.3.9 or 4.4.5, by version range2012-05-21
The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain se…
- CVE-2013-1842HIGHCVSS v2 7.5EG 7.5fixed in 4.5.24, 4.6.17, 4.7.9 or 6.0.3, by version range2013-03-20
SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related t…
- CVE-2013-1843MEDIUMCVSS v2 6.4EG 6.4fixed in 4.5.24, 4.6.17, 4.7.9 or 6.0.3, by version range2013-03-20
Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…
- CVE-2013-4320MEDIUMCVSS v2 5.5EG 5.5fixed in 6.0.9 or 6.1.4, by version range2014-05-20
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.
- CVE-2013-7077MEDIUMCVSS v2 4.3EG 4.3fixed in 6.0.12 or 6.1.7, by version range2013-12-21
Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2013-7078LOWCVSS v2 2.6EG 2.6fixed in 4.5.31, 4.7.16, 6.1.6 or 6.0.11, by version range2014-01-19
Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rew…
- CVE-2013-7080MEDIUMCVSS v2 5.8EG 5.8fixed in 4.5.31, 4.7.16 or 6.0.11, by version range2013-12-23
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the con…
- CVE-2013-7081MEDIUMCVSS v2 4.9EG 4.9fixed in 4.5.31, 4.7.16, 6.0.11 or 6.1.6, by version range2013-12-23
The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended acces…
- CVE-2018-14041MEDIUMCVSS 6.1EG 6.1fixed in 8.7.23 or 9.5.4, by version range2018-07-13
vulnerable: v9.0.0 ... v9.5.3 (13 versions)
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
- CVE-2018-17960MEDIUMCVSS 6.1EG 6.1fixed in 8.7.21 or 9.5.2, by version range2018-11-14
vulnerable: v9.0.0 ... v9.5.1 (11 versions)
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
- CVE-2019-10912HIGHCVSS 7.1EG 7.1fixed in 9.5.82019-05-16
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that t…
- CVE-2019-11832HIGHCVSS 7.5EG 7.5fixed in 8.7.25 or 9.5.6, by version range2019-05-09
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
- CVE-2019-12747HIGHCVSS 8.8EG 8.8fixed in 8.7.27 or 9.5.8, by version range2019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
- CVE-2019-12748MEDIUMCVSS 6.1EG 6.1fixed in 8.7.27 or 9.5.8, by version range2019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
- CVE-2019-19848HIGHCVSS 7.2EG 7.2fixed in 10.2.2, 8.7.30 or 9.5.12, by version range2019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privil…
- CVE-2019-19849HIGHCVSS 8.8EG 8.8fixed in 10.2.1, 8.7.30 or 9.5.12, by version range2019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires h…
- CVE-2019-19850HIGHCVSS 7.2EG 7.2fixed in 8.7.30, 9.5.12 or 10.2.2, by version range2019-12-17
vulnerable: v10.0.0, v10.1.0, v10.2.0, v10.2.1
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the …
- CVE-2020-11063LOWCVSS 3.7EG 3.7fixed in 10.4.22020-05-13
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2020-11064MEDIUMCVSS 5.4EG 5.4fixed in 9.5.17 or 10.4.2, by version range2020-05-13
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to …
- CVE-2020-11065MEDIUMCVSS 5.4EG 5.4fixed in 10.4.2 or 9.5.17, by version range2020-05-13
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; …
- CVE-2020-11066HIGHCVSS 8.7EG 8.7fixed in 9.5.17 or 10.4.2, by version range2020-05-14
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object …
- CVE-2020-11067HIGHCVSS 8.8EG 8.8fixed in 9.5.17 or 10.4.2, by version range2020-05-14
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, thi…
- CVE-2020-11069HIGHCVSS 8.0EG 8.0fixed in 9.5.17 or 10.4.2, by version range2020-05-14
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malic…
- CVE-2020-15098HIGHCVSS 8.8EG 8.8fixed in 9.5.20 or 10.4.6, by version range2020-07-29
vulnerable: v10.0.0 ... v10.4.5 (12 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This al…
- CVE-2020-15099HIGHCVSS 8.1EG 8.1fixed in 9.5.20 or 10.4.6, by version range2020-07-29
vulnerable: v10.0.0 ... v10.4.5 (12 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - eit…
- CVE-2020-15241MEDIUMCVSS 4.7EG 4.7fixed in 8.7.25 or 9.5.6, by version range2020-10-08
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? …
- CVE-2020-26227MEDIUMCVSS 6.1EG 6.1fixed in 9.5.23, 10.4.10 or 8.7.38, by version range2020-11-23
vulnerable: v8.7.10 ... v8.7.9 (26 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data …
- CVE-2020-26228HIGHCVSS 8.1EG 8.1fixed in 9.5.23, 10.4.10 or 8.7.38, by version range2020-11-23
vulnerable: v8.7.10 ... v8.7.9 (26 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vuln…
- CVE-2020-26229LOWCVSS 3.7EG 3.7fixed in 10.4.102020-11-23
vulnerable: v10.0.0 ... v10.4.9 (16 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical …
- CVE-2021-21338MEDIUMCVSS 4.7EG 4.7fixed in 6.2.57, 7.6.51, 8.7.40, 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers …
- CVE-2021-21339MEDIUMCVSS 5.9EG 5.9fixed in 6.2.57, 7.6.51, 8.7.40, 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic ha…
- CVE-2021-21340MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content get…
- CVE-2021-21355HIGHCVSS 8.6EG 8.6fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary …
- CVE-2021-21357HIGHCVSS 8.3EG 8.3fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data …
- CVE-2021-21358MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid bac…
- CVE-2021-21359MEDIUMCVSS 5.9EG 5.9fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to b…
- CVE-2021-21370MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their…
- CVE-2021-32667MEDIUMCVSS 6.4EG 6.4fixed in 9.5.28, 10.4.18 or 11.3.1, by version range2021-07-20
vulnerable: v11.0.0, v11.1.0, v11.1.1, v11.2.0, v11.3.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly enc…
- CVE-2021-32668MEDIUMCVSS 6.4EG 6.4fixed in 8.7.41, 9.5.28, 10.4.18 or 11.3.1, by version range2021-07-20
vulnerable: v11.0.0, v11.1.0, v11.1.1, v11.2.0, v11.3.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the …
- CVE-2021-32669MEDIUMCVSS 6.4EG 6.4fixed in 8.7.41, 9.5.28, 10.4.18 or 11.3.1, by version range2021-07-20
vulnerable: v11.0.0, v11.1.0, v11.1.1, v11.2.0, v11.3.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not proper…
- CVE-2021-32767MEDIUMCVSS 5.3EG 5.3fixed in 7.6.52, 8.7.41, 9.5.28, 10.4.18 or 11.3.1, by version range2021-07-20
vulnerable: v11.0.0, v11.1.0, v11.1.1, v11.2.0, v11.3.0
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log lev…
- CVE-2021-32768MEDIUMCVSS 6.1EG 6.1fixed in 7.6.53, 8.7.42, 10.4.19, 11.3.2 or 9.5.29, by version range2021-08-10
vulnerable: v9.0.0 ... v9.5.9 (38 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website front…
- CVE-2021-41113HIGHCVSS 8.8EG 8.8fixed in 11.5.02021-10-05
vulnerable: v11.2.0 ... v11.4.0 (6 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature that allows users to create and share deep links in the backend user interface is vulnerable …
- CVE-2021-41114MEDIUMCVSS 4.8EG 4.8fixed in 11.5.02021-10-05
vulnerable: v11.0.0 ... v11.4.0 (9 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP Host header. TYPO3 uses the HTTP Host …
- CVE-2022-23500MEDIUMCVSS 5.9EG 5.9fixed in 9.5.38, 10.4.33 or 11.5.20, by version range2022-12-14
vulnerable: v11.0.0 ... v11.5.9 (29 versions)
TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve c…
- CVE-2022-23501MEDIUMCVSS 5.9EG 5.9fixed in 8.7.49, 9.5.38, 10.4.33, 11.5.20 or 12.1.1, by version range2022-12-14
vulnerable: v12.0.0, v12.1.0
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in d…
- CVE-2022-23502MEDIUMCVSS 5.4EG 5.4fixed in 10.4.33, 11.5.20 or 12.1.1, by version range2022-12-14
vulnerable: v12.0.0, v12.1.0
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particu…
Check whether typo3/cms-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms-core CVEs against the assets you own.
Book a Demo →