TYPO3-CORE-SA-2021-006: Cleartext storage of session identifier
It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.
Read moreTYPO3-CORE-SA-2021-005: Denial of Service in Page Error Handling
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-CORE-SA-2021-004: Cross-Site Scripting in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2021-003: Broken Access Control in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to broken access control.
TYPO3-CORE-SA-2021-002: Unrestricted File Upload in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to unrestricted file upload.
TYPO3-CORE-SA-2021-001: Open Redirection in Login Handling
It has been discovered that TYPO3 CMS is susceptible to open redirection.
TYPO3 11.1.1, 10.4.14, 9.5.25 security releases published
The versions 11.1.1, 10.4.14, 9.5.25, 8.7.40, 7.6.51, 6.2.57 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-EXT-SA-2021-003: Cross-Site Scripting in extension "Aimeos shop and e-commerce framework" (aimeos)
It has been discovered that the extension"Aimeos shop and e-commerce framework" (aimeos) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2021-002: Denial of Service in extension "Code Highlight" (codehighlight)
It has been discovered that the extension "Code Highlight" (codehighlight) is susceptible to Denial of Service.
TYPO3-EXT-SA-2021-001: SQL Injection in extension "VHS: Fluid ViewHelpers" (vhs)
It has been discovered that the extension "VHS: Fluid ViewHelpers" (vhs) is susceptible to SQL Injection.