TYPO3-CORE-SA-2020-006: Same-Origin Request Forgery to Backend User Interface
It has been discovered that TYPO3 CMS is vulnerable to same-origin request forgery.
Read moreTYPO3-CORE-SA-2020-005: Insecure Deserialization in Backend User Settings
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2020-004: Class destructors causing side-effects when being unserialized
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2020-003: Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2020-002: Cross-Site Scripting in Form Engine
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2020-001: Information Disclosure in Password Reset
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2019-026: Insecure Deserialization in Query Generator & Query View
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2019-025: SQL Injection in low-level Query Generator
It has been discovered that TYPO3 CMS is vulnerable to SQL injection.
TYPO3-CORE-SA-2019-024: Directory Traversal on ZIP extraction
It has been discovered that TYPO3 CMS is vulnerable to directory traversal.
TYPO3-CORE-SA-2019-023: Cross-Site Scripting in Filelist Module
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.