Author: Torben Hansen
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-010: Insecure Direct Object Reference in extension "femanager" (femanager)
-
Torben Hansen
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
Read more- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-009: Insecure Direct Object Reference in extension "powermail" (powermail)
-
Torben Hansen
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-003: Multiple vulnerabilities in extension “[clickstorm] SEO” (cs_seo)
-
Torben Hansen
It has been discovered that the extension "[clickstorm] SEO" (cs_seo) is susceptible to Cross-Site Scripting and Insecure Direct Object Reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension “Additional TCA” (additional_tca)
-
Torben Hansen
It has been discovered that the extension “Additional TCA” (additional_tca) is susceptible to Cross-Site Scripting.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
-
Torben Hansen
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Account Takeover.
- Showcase & Success
- Product Updates & Roadmap
Double bug bounties for vulnerabilities in TYPO3 CMS until the end of 2024
-
Torben Hansen
-
Oliver Hader
The TYPO3 Security Team is doubling bug bounties for all verified vulnerabilities in TYPO3 CMS until December 31, 2024. This special campaign offers an opportunity for security researchers and ethical hackers to contribute to TYPO3’s security with enhanced rewards in recognition of their efforts.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension "powermail" (powermail)
-
Torben Hansen
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2024-006: Multiple vulnerabilities in "powermail" (powermail)
-
Torben Hansen
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference and Broken Access Control.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2024-005: Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos)
-
Torben Hansen
It has been discovered that the extension "Aimeos shop and e-commerce framework" (aimeos) is susceptible to Remote Code Execution and Insecure Direct Object Reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2024-004: Broken Access Control in "Integration of Friendly Captcha" (friendlycaptcha_official)
-
Torben Hansen
It has been discovered that the extension "Integration of Friendly Captcha" (friendlycaptcha_official) is susceptible to Broken Access Control.