TYPO3-PSA-2021-003: Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters
It has been discovered that TYPO3 CMS is susceptible to cache poisoning.
Read more- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2017-003: Cross-Site Scripting in TYPO3 CMS
It has been discovered, that TYPO3 is vulnerable to Cross-Site Scripting
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2017-002: Authentication Bypass in TYPO3 Frontend
It has been discovered, that TYPO3 CMS is vulnerable to Authentication Bypass.
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2017-001: Remote Code Execution in third party library swiftmailer
It has been discovered, that the third party package swiftmailer/swiftmailer is vulnerable to Remote Code Execution
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2016-024: Path Traversal in TYPO3 Core
It has been discovered, that TYPO3 is susceptible to Path Traversal.
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2016-023: Insecure Unserialize in TYPO3 Backend
It has been discovered, that TYPO3 is susceptible to Insecure Unserialize.
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2016-033: Unvalidated Redirect in extension "TC Directmail" (tcdirectmail)
It has been discovered that the extension "TC Directmail" (tcdirectmail) is susceptible to Unvalidated Redirect.
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2016-032: SQL Injection in extension "Member Infosheets" (if_membersheet)
It has been discovered that the extension "Member Infosheets" (if_membersheet) is susceptible to SQL Injection.
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2016-031: Cross Site-Scripting in extension "Secure Download Form" (rs_securedownload)
It has been discovered that the extension "Secure Download Form" (rs_securedownload) is susceptible to Cross Site-Scripting.
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2016-030: SQL Injection in extension "Shibboleth Authentication" (shibboleth_auth)
It has been discovered that the extension "Shibboleth Authentication" (shibboleth_auth) is susceptible to SQL Injection.