CVE-2021-21339
- EPSS 0.13%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:03
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algor...
CVE-2021-21340
- EPSS 0.38%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:03
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed...
CVE-2021-21355
- EPSS 0.42%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:11
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with a...
CVE-2021-21357
- EPSS 1.12%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:11
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form...
CVE-2021-21358
- EPSS 0.38%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:11
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user a...
CVE-2021-21359
- EPSS 0.75%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:11
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as ...
CVE-2021-21370
- EPSS 0.34%
- Veröffentlicht 23.03.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:13
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced...
CVE-2020-26229
- EPSS 0.27%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:35
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was no...
CVE-2020-26227
- EPSS 0.36%
- Veröffentlicht 23.11.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:35
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument...
CVE-2020-26228
- EPSS 0.18%
- Veröffentlicht 23.11.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:35
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability c...