Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-EXT-SA-2021-010: Cross-Site Scripting in Extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2021-009: Denial of Service in Extension "Deferred image processing" (deferred_image_processing)
It has been discovered that the extension "Deferred image processing" (deferred_image_processing) is susceptible to Denial of Service.
TYPO3-EXT-SA-2021-008: Sensitive Information Disclosure in “Extbase Yaml Routes” (routes)
It has been discovered that the extension “Extbase Yaml Routes” (routes) is susceptible to Sensitive Information Disclosure.
TYPO3-CORE-SA-2021-013: Cross-Site Scripting via Rich-Text Content
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-PSA-2021-002: CSV Code Injection
It has been discovered that the TYPO3 extensions offering a CSV export might create CSV files that can contain formulas executed in external applications.
TYPO3-PSA-2021-001: Sensitive links in search results of TYPO3 extension indexed_search
It has been discovered that the TYPO3 extension “Indexed Search” may index sensitive links under certain conditions.
TYPO3-CORE-SA-2021-012: Information Disclosure in User Authentication
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2021-011: Cross-Site Scripting in Backend Grid View
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2021-010: Cross-Site Scripting in Query Generator & Query View
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2021-009: Cross-Site Scripting in Page Preview
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.