Typo3

Typo3

218 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 08.10.2024 18:15:30
  • Zuletzt bearbeitet 03.09.2025 17:31:52

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages a...

  • EPSS 0.63%
  • Veröffentlicht 14.05.2024 16:17:25
  • Zuletzt bearbeitet 03.09.2025 17:34:06

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageContr...

  • EPSS 0.05%
  • Veröffentlicht 14.05.2024 16:17:25
  • Zuletzt bearbeitet 03.09.2025 17:33:35

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature...

  • EPSS 0.62%
  • Veröffentlicht 14.05.2024 16:17:24
  • Zuletzt bearbeitet 21.01.2025 16:08:57

TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, a...

  • EPSS 0.63%
  • Veröffentlicht 14.05.2024 16:17:24
  • Zuletzt bearbeitet 03.09.2025 17:34:28

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this ...

  • EPSS 0.69%
  • Veröffentlicht 05.03.2024 02:15:27
  • Zuletzt bearbeitet 15.09.2025 17:21:54

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed...

  • EPSS 0.23%
  • Veröffentlicht 13.02.2024 23:15:09
  • Zuletzt bearbeitet 21.11.2024 09:00:17

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference ...

  • EPSS 0.39%
  • Veröffentlicht 13.02.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 09:00:17

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using br...

  • EPSS 0.22%
  • Veröffentlicht 13.02.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 09:00:17

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the editing forms of the TYPO3 Install Tool user interface. This allowed attackers ...

  • EPSS 0.19%
  • Veröffentlicht 13.02.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 09:00:17

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and re...