<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – TYPO3 (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/typo3.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/typo3-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – TYPO3 (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-8727 – The Crawler extension passes the X-T3Crawler-Meta response header from crawled U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8727</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8727</strong></p>
  <p>The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46725 – The extension passes an attacker-controlled cookie directly to PHP's unserialize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46725</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46725</strong></p>
  <p>The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6553 – Changing backend users' passwords via the user settings module results in storin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6553</guid>
    <pubDate>Tue, 21 Apr 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6553</strong></p>
  <p>Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1323 – The extension fails to properly define allowed classes used when deserializing t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1323</guid>
    <pubDate>Tue, 17 Mar 2026 09:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1323</strong></p>
  <p>The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0859 – TYPO3's mail‑file spool deserialization flaw lets local users with write access ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0859</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0859</strong></p>
  <p>TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59022 – Backend users who had access to the recycler module could delete arbitrary data ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59022</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59022</strong></p>
  <p>Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavailable. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12998 – Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12998</guid>
    <pubDate>Wed, 12 Nov 2025 12:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12998</strong></p>
  <p>Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59017 – Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59017</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59017</strong></p>
  <p>Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9573 – The ns_backup extension through 13.0.2 for TYPO3 allows command injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9573</guid>
    <pubDate>Tue, 02 Sep 2025 09:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9573</strong></p>
  <p>The ns_backup extension through 13.0.2 for TYPO3 allows command injection.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48207 – The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Dire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48207</guid>
    <pubDate>Wed, 21 May 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48207</strong></p>
  <p>The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48205 – The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48205</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48205</strong></p>
  <p>The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48201 – The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48201</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48201</strong></p>
  <p>The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48200 – The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48200</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48200</strong></p>
  <p>The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47941 – TYPO3 is an open source, PHP based web content management system. In versions on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47941</guid>
    <pubDate>Tue, 20 May 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47941</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient enforcement of access restrictions on all backend routes. Successful exploitation requires valid backend user credentials, as MFA…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47940 – TYPO3 is an open source, PHP based web content management system. Starting in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47940</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47940</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-283</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55924 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55924</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55924</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55921 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55921</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55921</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47047 – An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47047</guid>
    <pubDate>Tue, 17 Sep 2024 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47047</strong></p>
  <p>An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all forms persisted by the extension. The fixed versions are 7.5.1, 8.5.1, 10.9.1, and 12.4.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45233 – An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45233</guid>
    <pubDate>Thu, 29 Aug 2024 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45233</strong></p>
  <p>An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the Powermail Frontend plugins, an unauthenticated attacker can exploit this to edit, update, delete, or export data of persisted fo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22188 – TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22188</guid>
    <pubDate>Tue, 05 Mar 2024 02:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22188</strong></p>
  <p>TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25121 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25121</guid>
    <pubDate>Tue, 13 Feb 2024 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25121</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compat…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35782 – The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35782</guid>
    <pubDate>Fri, 16 Jun 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35782</strong></p>
  <p>The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24814 – TYPO3 is a free and open source Content Management Framework released under the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24814</guid>
    <pubDate>Tue, 07 Feb 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24814</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject malicious content. In combination with the TypoScript setting `config.absRefPrefix=auto`, attackers can inject malicious…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25014 – An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25014</guid>
    <pubDate>Thu, 02 Feb 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25014</strong></p>
  <p>An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25013 – An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25013</guid>
    <pubDate>Thu, 02 Feb 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25013</strong></p>
  <p>An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47411 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47411</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47411</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47410 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47410</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47410</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47409 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47409</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47409</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47408 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47408</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47408</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23503 – TYPO3 is an open source PHP based web content management system. Versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23503</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23503</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35628 – A SQL injection issue was discovered in the lux extension before 17.6.1, and 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35628</guid>
    <pubDate>Tue, 12 Jul 2022 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35628</strong></p>
  <p>A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29601 – The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29601</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29601</strong></p>
  <p>The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29600 – The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29600</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29600</strong></p>
  <p>The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24980 – An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24980</guid>
    <pubDate>Sat, 19 Feb 2022 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24980</strong></p>
  <p>An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43564 – An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43564</guid>
    <pubDate>Wed, 10 Nov 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43564</strong></p>
  <p>An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the filename of uploaded files (e.g., uploads/tx_jobfair/cv.pdf).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43563 – An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43563</guid>
    <pubDate>Wed, 10 Nov 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43563</strong></p>
  <p>An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This allows an attacker to download various media files from the DAM system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43562 – An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43562</guid>
    <pubDate>Wed, 10 Nov 2021 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43562</strong></p>
  <p>An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote location and save it to a user-controlled filename, which may result in Remote Code Execution. A TYPO3 backend user accou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41113 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41113</guid>
    <pubDate>Tue, 05 Oct 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41113</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature that allows users to create and share deep links in the backend user interface is vulnerable to cross-site-request-forgery. The impact is the same as described in TYPO3-CORE-SA-2020-006 (CVE-2020-11069). However, it is not limited to the same site conte…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38623 – The deferred_image_processing (aka Deferred image processing) extension before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38623</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38623</strong></p>
  <p>The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38302 – The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38302</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38302</strong></p>
  <p>The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36793 – The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when Csrf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36793</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36793</strong></p>
  <p>The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36792 – The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36792</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36792</strong></p>
  <p>The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36789 – The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36789</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36789</strong></p>
  <p>The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36786 – The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36786</guid>
    <pubDate>Fri, 13 Aug 2021 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36786</strong></p>
  <p>The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21357 – TYPO3 is an open source PHP based web content management system. In TYPO3 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21357</guid>
    <pubDate>Tue, 23 Mar 2021 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21357</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form Designer backend module of the Form Framework. In the default configuration of the Form Framework this allows attackers to explicitly allow arbitrar…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21355 – TYPO3 is an open source PHP based web content management system. In TYPO3 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21355</guid>
    <pubDate>Tue, 23 Mar 2021 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21355</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_. Besides that, _Uploaded…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-28381 – The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28381</guid>
    <pubDate>Tue, 16 Mar 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-28381</strong></p>
  <p>The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26228 – TYPO3 is an open source PHP based web content management system. In TYPO3 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26228</guid>
    <pubDate>Mon, 23 Nov 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26228</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. U…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26216 – TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26216</guid>
    <pubDate>Tue, 17 Nov 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26216</strong></p>
  <p>TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities have been detected in Fluid: 1. TagBasedViewHelper allowed XSS through maliciously crafted additionalAttributes arrays by creating keys with attribute-closing quotes followed by HTML. When rendering such attributes, TagBuilder would not escape the keys.…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15099 – In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15099</guid>
    <pubDate>Wed, 29 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15099</strong></p>
  <p>In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - either by using a different existing vulnerability or in case the internal encryptionKey was exposed - it is possible to retrieve arbitrary files of a TYPO3 instal…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15098 – In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15098</guid>
    <pubDate>Wed, 29 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15098</strong></p>
  <p>In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This allows to inject arbitrary data having a valid cryptographic message authentication code (HMAC-SHA1) and can lead to various attack chains including potential pri…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15086 – In TYPO3 installations with the "mediace" extension from version 7.6.2 and befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15086</guid>
    <pubDate>Wed, 29 Jul 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15086</strong></p>
  <p>In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message authentication code and can lead to remote code execution. To successfully exploit this vulnerability, an attacker must h…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15515 – The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15515</guid>
    <pubDate>Tue, 07 Jul 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15515</strong></p>
  <p>The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11069 – In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11069</guid>
    <pubDate>Thu, 14 May 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11069</strong></p>
  <p>In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously managed to upload to the web server. Scripts are then executed with the privileges of the victims' user session. In a worst…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11067 – In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11067</guid>
    <pubDate>Thu, 14 May 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11067</strong></p>
  <p>In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability. This has been fixed in 9.5.17 and 10.4.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11066 – In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11066</guid>
    <pubDate>Thu, 14 May 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11066</strong></p>
  <p>In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering deletion of an arbitrary directory in the file system, if it is writable for the web server. It can also trigger message sub…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3642 – Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3642</guid>
    <pubDate>Sat, 08 Feb 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3642</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19850 – An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19850</guid>
    <pubDate>Tue, 17 Dec 2019 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19850</strong></p>
  <p>An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19849 – An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19849</guid>
    <pubDate>Tue, 17 Dec 2019 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19849</strong></p>
  <p>An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires having the system extension ext:lowlevel (Backend Module: DB Check) installed, with a valid backend user who has administrator privileges. The other exploitable…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19848 – An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19848</guid>
    <pubDate>Tue, 17 Dec 2019 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19848</strong></p>
  <p>An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3584 – The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3584</guid>
    <pubDate>Tue, 26 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3584</strong></p>
  <p>The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3583 – It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3583</guid>
    <pubDate>Tue, 26 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3583</strong></p>
  <p>It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4628 – TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4628</guid>
    <pubDate>Wed, 06 Nov 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4628</strong></p>
  <p>TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3668 – TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3668</guid>
    <pubDate>Mon, 04 Nov 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3668</strong></p>
  <p>TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3663 – TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3663</guid>
    <pubDate>Mon, 04 Nov 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3663</strong></p>
  <p>TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3662 – TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3662</guid>
    <pubDate>Mon, 04 Nov 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3662</strong></p>
  <p>TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16700 – The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16700</guid>
    <pubDate>Wed, 16 Oct 2019 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16700</strong></p>
  <p>The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16699 – The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16699</guid>
    <pubDate>Wed, 16 Oct 2019 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16699</strong></p>
  <p>The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16682 – The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16682</guid>
    <pubDate>Wed, 16 Oct 2019 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16682</strong></p>
  <p>The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12747 – TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12747</guid>
    <pubDate>Tue, 09 Jul 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12747</strong></p>
  <p>TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11832 – TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution becaus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11832</guid>
    <pubDate>Thu, 09 May 2019 05:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11832</strong></p>
  <p>TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11831 – The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11831</guid>
    <pubDate>Thu, 09 May 2019 04:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11831</strong></p>
  <p>The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11830 – PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) packa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11830</guid>
    <pubDate>Thu, 09 May 2019 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11830</strong></p>
  <p>PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7743 – An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7743</guid>
    <pubDate>Tue, 12 Feb 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7743</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-7400 – The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7400</guid>
    <pubDate>Fri, 29 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-7400</strong></p>
  <p>The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15363 – Directory traversal vulnerability in public/examples/resources/getsource.php in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15363</guid>
    <pubDate>Sun, 15 Oct 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15363</strong></p>
  <p>Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-14251 – Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Cla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14251</guid>
    <pubDate>Mon, 11 Sep 2017 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-14251</strong></p>
  <p>Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-1401 – Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_lda...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1401</guid>
    <pubDate>Mon, 28 Aug 2017 15:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-1401</strong></p>
  <p>Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7581 – SQL injection vulnerability in NewsController.php in the News module 5.3.2 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7581</guid>
    <pubDate>Fri, 07 Apr 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7581</strong></p>
  <p>SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5091 – Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5091</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5091</strong></p>
  <p>Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4607 – Unrestricted file upload vulnerability in the Frontend User Upload (feupload) ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4607</guid>
    <pubDate>Tue, 16 Jun 2015 16:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4607</strong></p>
  <p>Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4606 – Unrestricted file upload vulnerability in the Job Fair (jobfair) extension befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4606</guid>
    <pubDate>Tue, 16 Jun 2015 16:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4606</strong></p>
  <p>Unrestricted file upload vulnerability in the Job Fair (jobfair) extension before 1.0.1 for TYPO3, when using Apache with mod_mime, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the extension upload folder.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1405 – SQL injection vulnerability in the Content Rating Extbase extension 2.0.3 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1405</guid>
    <pubDate>Tue, 03 Feb 2015 16:59:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1405</strong></p>
  <p>SQL injection vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1403 – SQL injection vulnerability in the Content Rating extension 1.0.3 and earlier fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1403</guid>
    <pubDate>Tue, 03 Feb 2015 16:59:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1403</strong></p>
  <p>SQL injection vulnerability in the Content Rating extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-9509 – The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9509</guid>
    <pubDate>Sun, 04 Jan 2015 21:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-9509</strong></p>
  <p>The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8325 – The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8325</guid>
    <pubDate>Wed, 22 Oct 2014 14:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8325</strong></p>
  <p>The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denial of service (resource consumption) via vectors related to the PHP PCRE library.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-7201 – Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7201</guid>
    <pubDate>Fri, 10 Oct 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-7201</strong></p>
  <p>Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6298 – Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6298</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6298</strong></p>
  <p>Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6295 – SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6295</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6295</strong></p>
  <p>SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6293 – SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6293</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6293</strong></p>
  <p>SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6290 – The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6290</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6290</strong></p>
  <p>The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6288 – The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6288</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6288</strong></p>
  <p>The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to bypass the CAPTCHA protection mechanism via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3947 – Unrestricted file upload vulnerability in the powermail extension before 1.6.11 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3947</guid>
    <pubDate>Fri, 03 Oct 2014 14:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3947</strong></p>
  <p>Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6241 – SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6241</guid>
    <pubDate>Thu, 11 Sep 2014 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6241</strong></p>
  <p>SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6236 – Unspecified vulnerability in the LumoNet PHP Include (lumophpinclude) extension ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6236</guid>
    <pubDate>Thu, 11 Sep 2014 14:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6236</strong></p>
  <p>Unspecified vulnerability in the LumoNet PHP Include (lumophpinclude) extension before 1.2.1 for TYPO3 allows remote attackers to execute arbitrary scripts via vectors related to extension links.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6235 – Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6235</guid>
    <pubDate>Thu, 11 Sep 2014 14:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6235</strong></p>
  <p>Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6233 – SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6233</guid>
    <pubDate>Thu, 11 Sep 2014 14:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6233</strong></p>
  <p>SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-6231 – Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6231</guid>
    <pubDate>Thu, 11 Sep 2014 14:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-6231</strong></p>
  <p>Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3759 – Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3759</guid>
    <pubDate>Fri, 16 May 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3759</strong></p>
  <p>Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to execute arbitrary SQL commands via vectors related to the (1) search or (2) list functionality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-6288 – Unspecified vulnerability in the Apache Solr for TYPO3 (solr) extension before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6288</guid>
    <pubDate>Mon, 28 Oct 2013 22:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-6288</strong></p>
  <p>Unspecified vulnerability in the Apache Solr for TYPO3 (solr) extension before 2.8.3 for TYPO3 has unknown impact and remote attack vectors, related to "Insecure Unserialize."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6288">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
