<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – TYPO3</title>
  <link>https://cvedaily.com/pages/tags/typo3.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/typo3.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – TYPO3</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-8727 – The Crawler extension passes the X-T3Crawler-Meta response header from crawled U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8727</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8727</strong></p>
  <p>The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46725 – The extension passes an attacker-controlled cookie directly to PHP's unserialize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46725</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46725</strong></p>
  <p>The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46723 – The additional_tables configuration of the page and tt_content indexers accepts ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46723</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46723</strong></p>
  <p>The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6553 – Changing backend users' passwords via the user settings module results in storin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6553</guid>
    <pubDate>Tue, 21 Apr 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6553</strong></p>
  <p>Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1323 – The extension fails to properly define allowed classes used when deserializing t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1323</guid>
    <pubDate>Tue, 17 Mar 2026 09:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1323</strong></p>
  <p>The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0895 – The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0895</guid>
    <pubDate>Tue, 20 Jan 2026 08:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0895</strong></p>
  <p>The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to  TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted fro…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0859 – TYPO3's mail‑file spool deserialization flaw lets local users with write access ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0859</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0859</strong></p>
  <p>TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59022 – Backend users who had access to the recycler module could delete arbitrary data ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59022</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59022</strong></p>
  <p>Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavailable. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59021 – Backend users with access to the redirects module and write permission on the sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59021</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59021</strong></p>
  <p>Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs – facilitating phishing or other malicious redirect attacks. This issue affects TYPO3 CMS versions 1…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59020 – By exploiting the defVals parameter, attackers could bypass field‑level access c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59020</guid>
    <pubDate>Tue, 13 Jan 2026 12:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59020</strong></p>
  <p>By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12998 – Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12998</guid>
    <pubDate>Wed, 12 Nov 2025 12:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12998</strong></p>
  <p>Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59019 – Missing authorization checks in the CSV download feature of TYPO3 CMS versions 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59019</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59019</strong></p>
  <p>Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59018 – Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59018</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59018</strong></p>
  <p>Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59017 – Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59017</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59017</strong></p>
  <p>Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59016 – Error messages containing sensitive information in the File Abstraction Layer in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59016</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59016</strong></p>
  <p>Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59015 – A deterministic three‑character prefix in the Password Generation component of T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59015</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59015</strong></p>
  <p>A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-59014 – An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59014</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-59014</strong></p>
  <p>An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the bookmark toolbar.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59013 – An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59013</guid>
    <pubDate>Tue, 09 Sep 2025 09:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59013</strong></p>
  <p>An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9573 – The ns_backup extension through 13.0.2 for TYPO3 allows command injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9573</guid>
    <pubDate>Tue, 02 Sep 2025 09:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9573</strong></p>
  <p>The ns_backup extension through 13.0.2 for TYPO3 allows command injection.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7900 – The femanager extension for TYPO3 allows Insecure Direct Object Reference result...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7900</guid>
    <pubDate>Tue, 22 Jul 2025 11:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7900</strong></p>
  <p>The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7899 – The powermail extension for TYPO3 allows Insecure Direct Object Reference result...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7899</guid>
    <pubDate>Tue, 22 Jul 2025 11:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7899</strong></p>
  <p>The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48207 – The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Dire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48207</guid>
    <pubDate>Wed, 21 May 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48207</strong></p>
  <p>The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48206 – The ns_backup extension through 13.0.0 for TYPO3 allows XSS.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48206</guid>
    <pubDate>Wed, 21 May 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48206</strong></p>
  <p>The ns_backup extension through 13.0.0 for TYPO3 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48205 – The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48205</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48205</strong></p>
  <p>The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48204 – The ns_backup extension through 13.0.0 for TYPO3 allows command injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48204</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48204</strong></p>
  <p>The ns_backup extension through 13.0.0 for TYPO3 allows command injection.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48203 – The cs_seo extension through 9.2.0 for TYPO3 allows XSS.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48203</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48203</strong></p>
  <p>The cs_seo extension through 9.2.0 for TYPO3 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48202 – The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48202</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48202</strong></p>
  <p>The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48201 – The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48201</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48201</strong></p>
  <p>The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48200 – The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48200</guid>
    <pubDate>Wed, 21 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48200</strong></p>
  <p>The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47941 – TYPO3 is an open source, PHP based web content management system. In versions on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47941</guid>
    <pubDate>Tue, 20 May 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47941</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient enforcement of access restrictions on all backend routes. Successful exploitation requires valid backend user credentials, as MFA…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47940 – TYPO3 is an open source, PHP based web content management system. Starting in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47940</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47940</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-283</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47939 – TYPO3 is an open source, PHP based web content management system. By design, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47939</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47939</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction means it is possible to upload files that may be considered potentially harmful, such as executable…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-351</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47938 – TYPO3 is an open source, PHP based web content management system. Starting in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47938</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47938</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current password. When an administrator updates their own account or modifies other user accounts via the admin interface, the cur…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-620</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47937 – TYPO3 is an open source, PHP based web content management system. Starting in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47937</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47937</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction layer (DBAL), frontend user permissions are only applied via `FrontendGroupRestriction` to the first table. As a result, d…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47936 – TYPO3 is an open source, PHP based web content management system. In versions on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47936</guid>
    <pubDate>Tue, 20 May 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47936</strong></p>
  <p>TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, Webhooks are inherently vulnerable to Cross-Site Request Forgery (CSRF), which can be exploited by adversaries to target internal resources (e.g., localhost or other services on the local network). While this is not a vulnerability in TYPO3…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24856 – An issue was discovered in the oidc (aka OpenID Connect Authentication) extensio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24856</guid>
    <pubDate>Sun, 16 Mar 2025 04:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24856</strong></p>
  <p>An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements are met: (1) an attacker can anticipate the e-mail address of the user, (2) an attacker can register a public frontend user account using that e…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-348</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55945 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55945</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55945</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55924 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55924</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55924</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55923 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55923</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55923</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55922 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55922</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55922</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55921 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55921</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55921</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55920 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55920</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55920</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55894 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55894</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55894</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55893 – TYPO3 is a free and open source Content Management Framework. A vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55893</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55893</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55892 – TYPO3 is a free and open source Content Management Framework. Applications that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55892</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55892</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-55891 – TYPO3 is a free and open source Content Management Framework. It has been discov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55891</guid>
    <pubDate>Tue, 14 Jan 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-55891</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the problem described. There are no known workarounds for this vulnerability.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34537 – TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34537</guid>
    <pubDate>Mon, 28 Oct 2024 14:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34537</strong></p>
  <p>TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-47780 – TYPO3 is a free and open source Content Management Framework. Backend users coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47780</guid>
    <pubDate>Tue, 08 Oct 2024 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-47780</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 1…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47047 – An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47047</guid>
    <pubDate>Tue, 17 Sep 2024 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47047</strong></p>
  <p>An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all forms persisted by the extension. The fixed versions are 7.5.1, 8.5.1, 10.9.1, and 12.4.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45233 – An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45233</guid>
    <pubDate>Thu, 29 Aug 2024 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45233</strong></p>
  <p>An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the Powermail Frontend plugins, an unauthenticated attacker can exploit this to edit, update, delete, or export data of persisted fo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45232 – An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45232</guid>
    <pubDate>Thu, 29 Aug 2024 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45232</strong></p>
  <p>An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An unauthenticated attacker can use this to display the user-submitted data of all forms persisted by the extension. This can only be exploited when the extension is configured to save submitted form data…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38874 – An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38874</guid>
    <pubDate>Fri, 21 Jun 2024 07:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38874</strong></p>
  <p>An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38873 – An issue was discovered in the friendlycaptcha_official (aka Integration of Frie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38873</guid>
    <pubDate>Fri, 21 Jun 2024 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38873</strong></p>
  <p>An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34358 – TYPO3 is an enterprise content management system. Starting in version 9.0.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34358</guid>
    <pubDate>Tue, 14 May 2024 16:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34358</strong></p>
  <p>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34357 – TYPO3 is an enterprise content management system. Starting in version 9.0.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34357</guid>
    <pubDate>Tue, 14 May 2024 16:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34357</strong></p>
  <p>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with acces…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34356 – TYPO3 is an enterprise content management system. Starting in version 9.0.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34356</guid>
    <pubDate>Tue, 14 May 2024 16:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34356</strong></p>
  <p>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LT…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-34355 – TYPO3 is an enterprise content management system. Starting in version 13.0.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34355</guid>
    <pubDate>Tue, 14 May 2024 16:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-34355</strong></p>
  <p>TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes th…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22188 – TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22188</guid>
    <pubDate>Tue, 05 Mar 2024 02:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22188</strong></p>
  <p>TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25121 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25121</guid>
    <pubDate>Tue, 13 Feb 2024 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25121</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compat…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25120 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25120</guid>
    <pubDate>Tue, 13 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25120</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25119 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25119</guid>
    <pubDate>Tue, 13 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25119</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the editing forms of the TYPO3 Install Tool user interface. This allowed attackers to utilize the value to generate cryptographic hashes used for verifying the authenticity of HTTP request parameters. Exploiting this vulnerability r…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25118 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25118</guid>
    <pubDate>Tue, 13 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25118</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using brute force techniques. Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS,…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24751 – sf_event_mgt is an event management and registration extension for the TYPO3 CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24751</guid>
    <pubDate>Tue, 13 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24751</strong></p>
  <p>sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30451 – In TYPO3 11.5.24, the filelist component allows attackers (who have access to th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30451</guid>
    <pubDate>Mon, 25 Dec 2023 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30451</strong></p>
  <p>In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28604 – The fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28604</guid>
    <pubDate>Tue, 12 Dec 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28604</strong></p>
  <p>The fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 allows XSS via a component argument parameter, for certain {content} use cases that may be edge cases.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-44543 – The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44543</guid>
    <pubDate>Tue, 12 Dec 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-44543</strong></p>
  <p>The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47127 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47127</guid>
    <pubDate>Tue, 14 Nov 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47127</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can be reused on the second site without requiring additional authentication. This vulnerability has been addressed in versi…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-47126 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47126</guid>
    <pubDate>Tue, 14 Nov 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-47126</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. This issue has been addressed in version 1…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47125 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47125</guid>
    <pubDate>Tue, 14 Nov 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47125</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerabilit…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41100 – An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41100</guid>
    <pubDate>Wed, 23 Aug 2023 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41100</strong></p>
  <p>An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check that the required captcha field is submitted in the form data. allowing a remote user to bypass the CAPTCHA check.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38500 – TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38500</guid>
    <pubDate>Tue, 25 Jul 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38500</strong></p>
  <p>TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a `noscript` element was not encoded correctly. `noscript` is disabled in the default c…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-38499 – TYPO3 is an open source PHP based web content management system. Starting in ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38499</guid>
    <pubDate>Tue, 25 Jul 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-38499</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handc…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-35783 – The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35783</guid>
    <pubDate>Fri, 16 Jun 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-35783</strong></p>
  <p>The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35782 – The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35782</guid>
    <pubDate>Fri, 16 Jun 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35782</strong></p>
  <p>The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2016-15032 – ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-15032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-15032</guid>
    <pubDate>Fri, 02 Jun 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2016-15032</strong></p>
  <p>** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. This affects the function stopOutput of the file class.tx_mhhttpbl.php. The manipulation of the argument $_SERVER['REMOTE_ADDR'] leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.1.8 is able to address thi…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-15032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-10106 – ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-10106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-10106</guid>
    <pubDate>Sun, 28 May 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-10106</strong></p>
  <p>** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. This vulnerability affects the function moduleContent of the file mod1/index.php. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.8 is able to address this issue. The patch is identified as 429f50f4e4795b20dae…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-10106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26091 – The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26091</guid>
    <pubDate>Sun, 26 Feb 2023 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26091</strong></p>
  <p>The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24814 – TYPO3 is a free and open source Content Management Framework released under the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24814</guid>
    <pubDate>Tue, 07 Feb 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24814</strong></p>
  <p>TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject malicious content. In combination with the TypoScript setting `config.absRefPrefix=auto`, attackers can inject malicious…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25014 – An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25014</guid>
    <pubDate>Thu, 02 Feb 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25014</strong></p>
  <p>An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25013 – An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25013</guid>
    <pubDate>Thu, 02 Feb 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25013</strong></p>
  <p>An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-15017 – A vulnerability has been found in fabarea media_upload on TYPO3 and classified a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-15017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-15017</guid>
    <pubDate>Tue, 10 Jan 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-15017</strong></p>
  <p>A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrading to version 0.9.0 is able to address this issue. The patch is identified as b25d42a4981072321c1a363311d8ea2a4ac8763a. It is recommended to up…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-21</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-15017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-25094 – A vulnerability, which was classified as problematic, was found in innologi appo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25094</guid>
    <pubDate>Wed, 04 Jan 2023 10:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-25094</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.6 is able to address this issue. The identifier of the patch is…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47411 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47411</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47411</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47410 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47410</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47410</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47409 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47409</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47409</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-47408 – An issue was discovered in the fp_newsletter (aka Newsletter subscriber manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47408</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-47408</strong></p>
  <p>An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-47407 – An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47407</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-47407</strong></p>
  <p>An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-47406 – An issue was discovered in the fe_change_pwd (aka Change password for frontend u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47406</guid>
    <pubDate>Wed, 14 Dec 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-47406</strong></p>
  <p>An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23504 – TYPO3 is an open source PHP based web content management system. Versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23504</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23504</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module, attackers could expose sensitive internal information, such as system configuration or HTTP request messages of othe…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23503 – TYPO3 is an open source PHP based web content management system. Versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23503</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23503</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23502 – TYPO3 is an open source PHP based web content management system. In versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23502</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23502</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This applied to both frontend user sessions and backend user sessions. This issue is patched in versions 10.4.33, 11.5.20, 12…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23501 – TYPO3 is an open source PHP based web content management system. In versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23501</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23501</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - howeve…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23500 – TYPO3 is an open source PHP based web content management system. In versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23500</guid>
    <pubDate>Wed, 14 Dec 2022 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23500</strong></p>
  <p>TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to be shown as an error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impac…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23499 – HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23499</guid>
    <pubDate>Tue, 13 Dec 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23499</strong></p>
  <p>HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1,  malicious markup used in a sequence with special HTML CDATA sections cannot be filtered and sanitized due to a parsing issue in the upstream package masterminds/html5. This allows bypassing the cross-site scripting mechanism of typo3/ht…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36108 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36108</guid>
    <pubDate>Tue, 13 Sep 2022 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36108</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or 11.5.16 that fix the problem. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36107 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36107</guid>
    <pubDate>Tue, 13 Sep 2022 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36107</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid backend user account is needed to exploit this vulnerability. Update to TYPO3 version 7.6.58 ELTS, 8.7.48 ELTS, 9.5.37 E…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36106 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36106</guid>
    <pubDate>Tue, 13 Sep 2022 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36106</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password reset link could be used to perform a password reset even if the default expiry time of two hours has been exceeded. Update to TYPO3 version 10.4.32 or 11.5.16…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36105 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36105</guid>
    <pubDate>Tue, 13 Sep 2022 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36105</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing and non-existing user accounts. Extension authors of 3rd party TYPO3 extensions providing a custom authentication service should check if the extension is affect…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36104 – TYPO3 is an open source PHP based web content management system released under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36104</guid>
    <pubDate>Tue, 13 Sep 2022 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36104</strong></p>
  <p>TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as an error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the ini…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36020 – The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36020</guid>
    <pubDate>Tue, 13 Sep 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36020</strong></p>
  <p>The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows for a bypass of the cross-site scripting mechanism of `typo3…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36020">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
