Security Advisories
All Advisories
TYPO3-CORE-SA-2020-002: Cross-Site Scripting in Form Engine
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
Mehr erfahrenTYPO3-EXT-SA-2020-006: Broken Access Control in extension "gForum" (g_forum)
It has been discovered that the extension "gForum" (g_forum) is susceptible to Broken Access Control.
TYPO3-CORE-SA-2020-001: Information Disclosure in Password Reset
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2020-005: Multiple vulnerabilities in extension "Direct Mail" (direct_mail)
It has been discovered that the extension "Direct Mail" (direct_mail) is susceptible to Denial of Service, Broken Access Control, Open Redirect and Information Disclosure.
TYPO3-EXT-SA-2020-004: SQL Injection in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to SQL Injection.
TYPO3-EXT-SA-2020-003: Multiple vulnerabilities in extension "Magalone Flipbook for TYPO3" (magaloneflipbook)
It has been discovered that the extension "Magalone Flipbook for TYPO3" (magaloneflipbook) is susceptible to Remote Code Execution, Arbitrary File Upload, Path Traversal and Broken Access Control.
TYPO3-EXT-SA-2020-002: Remote Code Execution in extension "PHPUnit" (phpunit)
It has been discovered that the extension "PHPUnit" (phpunit) is susceptible to Remote Code Execution.
TYPO3-EXT-SA-2020-001: SQL Injection in extension "phpmyadmin" (phpmyadmin)
It has been discovered that the extension "phpmyadmin" (phpmyadmin) is susceptible to SQL Injection.
TYPO3-EXT-SA-2019-023: CSRF in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Cross-Site-Request-Forgery (CSRF).
TYPO3-EXT-SA-2019-022: Privilege Escalation in extension "femanager direct mail subscription" (femanager_dmail_subscribe)
It has been discovered that the extension "femanager direct mail subscription" (femanager_dmail_subscribe) is susceptible to Privilege Escalation.