Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-EXT-SA-2011-011: Multiple XSS vulnerabilities in extension phpMyAdmin (phpmyadmin)
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to Cross-Site Scripting.
TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core
It has been discovered that TYPO3 is susceptible to Cache Flooding
TYPO3-CORE-SA-2011-002: Potential SQL injection vulnerability in TYPO3 Core
It has been discovered that the TYPO3 prepared statement database API allows SQL Injections.
TYPO3-EXT-SA-2011-009: Several Vulnerabilities in extension MailformPlus (th_mailformplus)
Several vulnerabilities have been found in the following third-party TYPO3 extension: th_mailformplus
TYPO3-EXT-SA-2011-008: Several Vulnerabilities in extension SmoothGallery for TYPO3 (rgsmoothgallery)
Several vulnerabilities have been found in the following third-party TYPO3 extension: rgsmoothgallery
TYPO3-EXT-SA-2011-007: Several Vulnerabilities in extension Direct Mail Subscription (direct_mail_subscription)
Several vulnerabilities have been found in the following third-party TYPO3 extension: direct_mail_subscription
TYPO3-EXT-SA-2011-010: A vulnerability in extension Drag Drop Mass Upload (ameos_dragndropupload)
A vulnerability has been found in the following third-party TYPO3 extension: ameos_dragndropupload