Author: Marcus Krause
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-008: Multiple vulnerabilities in extension "Front End User Registration" (sr_feuser_register)
-
Marcus Krause
It has been discovered that the extension "Front End User Registration" (sr_feuser_register) is susceptible to Remote Code Execution and Insecure Direct Object Reference.
Read more- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-007: Multiple vulnerabilities in extension "Backup Plus" (ns_backup)
-
Marcus Krause
It has been discovered that the extension "Backup Plus" (ns_backup) is susceptible to Command Injection, Predictable Resource Location and Cross-Site Scripting.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-006: Insecure Direct Object Reference in extension "femanager" (femanager)
-
Marcus Krause
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-005: Cross-Site Scripting in extension "[clickstorm] SEO" (cs_seo)
-
Marcus Krause
It has been discovered that the extension "[clickstorm] SEO" (cs_seo) is susceptible to Cross-Site Scripting.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-004: Insecure Direct Object Reference in extension "Download manager" (reint_downloadmanager)
-
Marcus Krause
It has been discovered that the extension "Download manager" (reint_downloadmanager) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- Product Updates & Roadmap
- Public Service Announcement
TYPO3-PSA-2021-003: Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters
-
Marcus Krause
It has been discovered that TYPO3 CMS is susceptible to cache poisoning.
- Product Updates & Roadmap
- TYPO3 CMS
TYPO3-CORE-SA-2017-003: Cross-Site Scripting in TYPO3 CMS
-
Marcus Krause
It has been discovered, that TYPO3 is vulnerable to Cross-Site Scripting
- Product Updates & Roadmap
- TYPO3 CMS
TYPO3-CORE-SA-2017-002: Authentication Bypass in TYPO3 Frontend
-
Marcus Krause
It has been discovered, that TYPO3 CMS is vulnerable to Authentication Bypass.
- Product Updates & Roadmap
- TYPO3 CMS
TYPO3-CORE-SA-2017-001: Remote Code Execution in third party library swiftmailer
-
Marcus Krause
It has been discovered, that the third party package swiftmailer/swiftmailer is vulnerable to Remote Code Execution
- Product Updates & Roadmap
- TYPO3 CMS
TYPO3-CORE-SA-2016-024: Path Traversal in TYPO3 Core
-
Marcus Krause
It has been discovered, that TYPO3 is susceptible to Path Traversal.