TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling
It has been discovered that TYPO3 CMS can be vulnerable to insecure deserialization.
Read moreTYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling
It has been discovered that TYPO3 is susceptible to cross-site scripting.
TYPO3-PSA-2019-009: Truncated passwords during authentication process on typo3.org services
It has been discovered that passwords were truncated during authentication process on typo3.org services.
TYPO3-PSA-2019-008: By-passing protection of Phar Stream Wrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
TYPO3-PSA-2019-006: Security Misconfiguration since TYPO3 9.4.0
It has been discovered that TYPO3 is susceptible to security misconfiguration.
TYPO3-PSA-2019-005: Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0
It has been discovered that 3rd party library Bootstrap CSS toolkit bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
TYPO3-PSA-2019-004: Cross-Site Scripting in jQuery before 3.4.0
It has been discovered that 3rd party library jQuery bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
TYPO3-PSA-2019-001: Possible Arbitrary Code Execution in CommandUtility API
It has been discovered that TYPO3 CMS can be vulnerable to arbitrary code execution.
TYPO3-PSA-2019-002: Username and Email Address Enumeration
It has been discovered, that usernames and email addresses may be enumerated with brute-force techniques, when using validators in order to ensure a unique username or email address.