Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-EXT-SA-2011-006: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: MM DAM - FEFileList (mm_dam_filelist), Events (julle_events), WEC Staff Directory (wec_staffdirectory), TGM news (tgm_news), TGM media (tgm_media), TGM calendar module (tgm_cal), DAM Lightbox (damlightbox), Download system (sb_downloader), iwbase (iwbase), Fussballtippspiel (toto), Font resizer (fontsizer), Adminer (t3adminer)
TYPO3-EXT-SA-2011-005: Multiple XSS vulnerabilities in extension phpMyAdmin (phpmyadmin)
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to Cross-Site Scripting.
TYPO3-EXT-SA-2011-004: Cross Site Scripting Vulnerability in extension Questionaire (pbsurvey)
It has been discovered that the extension "Questionaire" (pbsurvey) is vulnerable to Cross-Site Scripting.
TYPO3-EXT-SA-2011-003: Several Vulnerabilities in extension Formhandler (formhandler)
It has been discovered that the extension Formhandler (formhandler) is vulnerable to SQL-Injection and Cross-Site Scripting.
TYPO3-EXT-SA-2011-002: Multiple SQL Injection vulnerabilities in extension "Website Photo Gallery" (jm_gallery)
It has been discovered that the extension Website Photo Gallery (jm_gallery) is vulnerable to SQL injection.
TYPO3-CORE-SA-2011-001: Multiple vulnerabilities in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Cross-Site Scripting (XSS), Information Disclosure, Authentication Delay Bypass, Unserialize() vulnerability, Missing Access Control.