typo3/cms
Packagist116 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cmspage 2 of 3
- CVE-2014-9509HIGHCVSS v2 7.5EG 7.5fixed in 4.5.39, 6.2.9, 7.0.2, 4.6.19, 4.7.21, 6.0.15 or 6.1.13, by version range2015-01-04
vulnerable: 7.0.0, 7.0.1
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly …
- CVE-2015-5956LOWCVSS v2 3.5EG 3.5fixed in 6.2.15 or 7.4.0, by version range2015-09-16
vulnerable: 7.0.0 ... 7.3.1 (7 versions)
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as dem…
- CVE-2015-8755MEDIUMCVSS 5.4EG 5.4fixed in 6.2.16 or 7.6.1, by version range2016-01-08
vulnerable: 7.0.0 ... 7.6.0 (10 versions)
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
- CVE-2015-8756MEDIUMCVSS 5.4EG 5.4fixed in 6.2.162016-01-08
vulnerable: 6.2.0 ... 6.2.9 (17 versions)
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vec…
- CVE-2015-8759MEDIUMCVSS 5.4EG 5.4fixed in 6.2.16 or 7.6.1, by version range2016-01-08
vulnerable: 7.0.0 ... 7.6.0 (10 versions)
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.
- CVE-2015-8760MEDIUMCVSS 6.1EG 6.1fixed in 6.2.162016-01-08
vulnerable: 6.2.0 ... 6.2.9 (17 versions)
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."
- CVE-2016-4056MEDIUMCVSS 6.1EG 6.1fixed in 6.2.192017-01-23
vulnerable: 6.2.0 ... 6.2.9 (20 versions)
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
- CVE-2017-14251HIGHCVSS 8.8EG 8.8fixed in 7.6.22 or 8.7.5, by version range2017-09-11
vulnerable: 8.0.0 ... v8.7.4 (20 versions)
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and …
- CVE-2017-6370MEDIUMCVSS 5.3EG 5.32017-03-17
vulnerable: 7.6.15
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fie…
- CVE-2018-14041MEDIUMCVSS 6.1EG 6.1fixed in 8.7.23 or 9.5.4, by version range2018-07-13
vulnerable: v9.0.0 ... v9.5.3 (13 versions)
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
- CVE-2018-17960MEDIUMCVSS 6.1EG 6.1fixed in 8.7.21 or 9.5.2, by version range2018-11-14
vulnerable: v9.0.0 ... v9.5.1 (11 versions)
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
- CVE-2018-6905MEDIUMCVSS 4.8EG 4.8fixed in 9.2.02018-04-08
vulnerable: 6.2.0 ... v9.1.0 (125 versions)
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
- CVE-2019-10912HIGHCVSS 7.1EG 7.1fixed in 9.5.82019-05-16
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that t…
- CVE-2019-11832HIGHCVSS 7.5EG 7.5fixed in 8.7.25 or 9.5.6, by version range2019-05-09
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
- CVE-2019-12747HIGHCVSS 8.8EG 8.8fixed in 8.7.27 or 9.5.8, by version range2019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
- CVE-2019-12748MEDIUMCVSS 6.1EG 6.1fixed in 8.7.27 or 9.5.8, by version range2019-07-09
vulnerable: v9.0.0 ... v9.5.7 (17 versions)
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
- CVE-2019-19848HIGHCVSS 7.2EG 7.2fixed in 10.2.2, 8.7.30 or 9.5.12, by version range2019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privil…
- CVE-2019-19849HIGHCVSS 8.8EG 8.8fixed in 10.2.1, 8.7.30 or 9.5.12, by version range2019-12-17
vulnerable: v9.0.0 ... v9.5.9 (21 versions)
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires h…
- CVE-2019-19850HIGHCVSS 7.2EG 7.2fixed in 8.7.30, 9.5.12 or 10.2.2, by version range2019-12-17
vulnerable: v10.0.0, v10.1.0, v10.2.0, v10.2.1
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the …
- CVE-2020-11063LOWCVSS 3.7EG 3.7fixed in 10.4.22020-05-13
vulnerable: v10.0.0 ... v10.4.1 (8 versions)
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2020-11064MEDIUMCVSS 5.4EG 5.4fixed in 10.4.2 or 9.5.17, by version range2020-05-13
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to …
- CVE-2020-11065MEDIUMCVSS 5.4EG 5.4fixed in 10.4.2 or 9.5.17, by version range2020-05-13
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; …
- CVE-2020-11066HIGHCVSS 8.7EG 8.7fixed in 10.4.2 or 9.5.17, by version range2020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object …
- CVE-2020-11067HIGHCVSS 8.8EG 8.8fixed in 10.4.2 or 9.5.17, by version range2020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, thi…
- CVE-2020-11069HIGHCVSS 8.0EG 8.0fixed in 10.4.2 or 9.5.17, by version range2020-05-14
vulnerable: v9.0.0 ... v9.5.9 (26 versions)
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malic…
- CVE-2020-15098HIGHCVSS 8.8EG 8.8fixed in 10.4.6 or 9.5.20, by version range2020-07-29
vulnerable: v9.0.0 ... v9.5.9 (29 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This al…
- CVE-2020-15099HIGHCVSS 8.1EG 8.1fixed in 10.4.6 or 9.5.20, by version range2020-07-29
vulnerable: v9.0.0 ... v9.5.9 (29 versions)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - eit…
- CVE-2020-15241MEDIUMCVSS 4.7EG 4.7fixed in 8.7.25 or 9.5.6, by version range2020-10-08
vulnerable: v9.0.0 ... v9.5.5 (15 versions)
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? …
- CVE-2020-26227MEDIUMCVSS 6.1EG 6.1fixed in 10.4.10, 9.5.23 or 8.7.38, by version range2020-11-23
vulnerable: 8.7.0 ... v8.7.9 (33 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data …
- CVE-2020-26228HIGHCVSS 8.1EG 8.1fixed in 10.4.10, 9.5.23 or 8.7.38, by version range2020-11-23
vulnerable: 8.7.0 ... v8.7.9 (33 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vuln…
- CVE-2020-26229LOWCVSS 3.7EG 3.7fixed in 10.4.102020-11-23
vulnerable: v10.0.0 ... v10.4.9 (16 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical …
- CVE-2020-8091MEDIUMCVSS 6.1EG 6.1fixed in 7.2.0 or 6.2.39, by version range2020-01-27
vulnerable: 6.2.0 ... 6.2.9 (33 versions)
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.
- CVE-2021-21338MEDIUMCVSS 4.7EG 4.7fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers …
- CVE-2021-21339MEDIUMCVSS 5.9EG 5.9fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic ha…
- CVE-2021-21340MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content get…
- CVE-2021-21355HIGHCVSS 8.6EG 8.6fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary …
- CVE-2021-21357HIGHCVSS 8.3EG 8.3fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data …
- CVE-2021-21358MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid bac…
- CVE-2021-21359MEDIUMCVSS 5.9EG 5.9fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to b…
- CVE-2021-21370MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14, 11.1.1 or 9.5.25, by version range2021-03-23
vulnerable: v9.0.0 ... v9.5.9 (34 versions)
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their…
- CVE-2021-32667MEDIUMCVSS 6.4EG 6.4fixed in 10.4.18, 11.3.1 or 9.5.28, by version range2021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly enc…
- CVE-2021-32668MEDIUMCVSS 6.4EG 6.4fixed in 10.4.18, 11.3.1 or 9.5.28, by version range2021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the …
- CVE-2021-32669MEDIUMCVSS 6.4EG 6.4fixed in 10.4.18, 11.3.1 or 9.5.28, by version range2021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not proper…
- CVE-2021-32767MEDIUMCVSS 5.3EG 5.3fixed in 10.4.18, 11.3.1 or 9.5.28, by version range2021-07-20
vulnerable: v9.0.0 ... v9.5.9 (37 versions)
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log lev…
- CVE-2021-32768MEDIUMCVSS 6.1EG 6.1fixed in 10.4.19, 11.3.2, 9.5.29, 8.7.42 or 7.6.53, by version range2021-08-10
vulnerable: 7.0.0 ... v7.6.32 (42 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website front…
- CVE-2021-41113HIGHCVSS 8.8EG 8.8fixed in 11.5.02021-10-05
vulnerable: v11.2.0 ... v11.4.0 (6 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature that allows users to create and share deep links in the backend user interface is vulnerable …
- CVE-2021-41114MEDIUMCVSS 4.8EG 4.8fixed in 11.5.02021-10-05
vulnerable: v11.0.0 ... v11.4.0 (9 versions)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP Host header. TYPO3 uses the HTTP Host …
- CVE-2022-23499MEDIUMCVSS 6.1EG 6.1fixed in 10.4.33, 11.5.20 or 12.1.1, by version range2022-12-13
vulnerable: v12.0.0, v12.1.0
HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1, malicious markup used in a sequence with special HTML CDATA sections cannot …
- CVE-2022-23500MEDIUMCVSS 5.9EG 5.9fixed in 10.4.33 or 11.5.20, by version range2022-12-14
vulnerable: v11.0.0 ... v11.5.9 (29 versions)
TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve c…
- CVE-2022-23501MEDIUMCVSS 5.9EG 5.9fixed in 10.4.33, 11.5.20 or 12.1.1, by version range2022-12-14
vulnerable: v12.0.0, v12.1.0
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in d…
Check whether typo3/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms CVEs against the assets you own.
Book a Demo →