<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Neos</title>
  <link>https://cvedaily.com/pages/tags/neos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/neos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Neos</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-4143 – The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4143</guid>
    <pubDate>Sat, 21 Mar 2026 04:17:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4143</strong></p>
  <p>The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request, granted they can trick a site administrator i…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-37611 – Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37611</guid>
    <pubDate>Mon, 18 Sep 2023 22:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-37611</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-30429 – Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30429</guid>
    <pubDate>Thu, 02 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-30429</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all intermediate versions.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32697 – neos/forms is an open source framework to build web forms. By crafting a special...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32697</guid>
    <pubDate>Mon, 21 Jun 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32697</strong></p>
  <p>neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side effects even if no form values have been sent. Form Finishers can be adjusted i…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2821 – TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2821</guid>
    <pubDate>Wed, 01 Apr 2015 14:59:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2821</strong></p>
  <p>TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2821">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
