CVE-2024-55894
- EPSS 0.1%
- Veröffentlicht 14.01.2025 20:15:29
- Zuletzt bearbeitet 26.08.2025 19:34:35
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). ...
CVE-2024-55920
- EPSS 0.05%
- Veröffentlicht 14.01.2025 20:15:29
- Zuletzt bearbeitet 26.08.2025 19:34:46
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). ...
CVE-2024-55921
- EPSS 0.15%
- Veröffentlicht 14.01.2025 20:15:29
- Zuletzt bearbeitet 26.08.2025 19:34:53
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). ...
CVE-2024-55891
- EPSS 0.1%
- Veröffentlicht 14.01.2025 20:15:28
- Zuletzt bearbeitet 26.08.2025 18:52:53
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update t...
CVE-2024-55892
- EPSS 0.09%
- Veröffentlicht 14.01.2025 20:15:28
- Zuletzt bearbeitet 26.08.2025 18:55:45
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect o...
CVE-2024-34537
- EPSS 0.25%
- Veröffentlicht 28.10.2024 14:15:04
- Zuletzt bearbeitet 03.09.2025 17:31:07
TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fix...
CVE-2024-47780
- EPSS 0.19%
- Veröffentlicht 08.10.2024 18:15:30
- Zuletzt bearbeitet 03.09.2025 17:31:52
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages a...
CVE-2024-34357
- EPSS 0.63%
- Veröffentlicht 14.05.2024 16:17:25
- Zuletzt bearbeitet 03.09.2025 17:34:06
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageContr...
CVE-2024-34358
- EPSS 0.05%
- Veröffentlicht 14.05.2024 16:17:25
- Zuletzt bearbeitet 03.09.2025 17:33:35
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature...
CVE-2024-34355
- EPSS 0.62%
- Veröffentlicht 14.05.2024 16:17:24
- Zuletzt bearbeitet 21.01.2025 16:08:57
TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, a...