TYPO3-EXT-SA-2020-015: Cross-Site Scripting in extension "Kitodo.Presentation" (dlf)
It has been discovered that the extension "Kitodo.Presentation" (dlf) is susceptible to Cross-Site Scripting.
Read moreTYPO3 10.4.6 and 9.5.20 security releases published
The versions 10.4.6 and 9.5.20 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2020-008: Sensitive Information Disclosure
It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure.
TYPO3-CORE-SA-2020-007: Potential Privilege Escalation
It has been discovered that TYPO3 CMS is susceptible to privilege escalation.
TYPO3-EXT-SA-2020-014: Sensitive Information Disclosure in extension "Media Content Element" (mediace)
It has been discovered that the extension "Media Content Element" (mediace) is susceptible to Sensitive Information Disclosure.
TYPO3-PSA-2020-001: Critical vulnerability in legacy versions of TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure in previous TYPO3 versions which are not maintained by the community anymore.
TYPO3-EXT-SA-2020-013: Multiple vulnerabilities in extension "mm_forum" (mm_forum)
It has been discovered that the extension "mm_forum" (mm_forum) is susceptible to Cross Site Scripting and CSRF.
TYPO3-EXT-SA-2020-012: Cross-Site Scripting in extension "Google reCAPTCHA (v2/v3)" (jh_captcha)
It has been discovered that the extension "Google reCAPTCHA (v2/v3)" (jh_captcha) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2020-011: Remote Code Execution in extension "Turn!" (turn)
It has been discovered that the extension "Turn!" (turn) is susceptible to Remote Code Execution.
TYPO3-EXT-SA-2020-010: Broken Access Control in extension "typo3_forum" (typo3_forum)
It has been discovered that the extension "typo3_forum" (typo3_forum) is susceptible to Broken Access Control.