Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-EXT-SA-2011-012: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: mm_hutinfo, np_indexed_search_stat, rzcolorbox, t3c_podcasts, winning_game, tgm_gallery, tgmv_gallery, bps_shib, dev_null_robots, dhc_inflationcal, dam_frontend, rtg_files, mg_rooms, gridelements
TYPO3-EXT-SA-2011-013: Cross-Site scripting vulnerability in extension t3blog (t3blog)
It has been discovered that the extension "T3Blog" (t3blog) is vulnerable to Cross-Site Scripting.
TYPO3-EXT-SA-2011-011: Multiple XSS vulnerabilities in extension phpMyAdmin (phpmyadmin)
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to Cross-Site Scripting.
TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core
It has been discovered that TYPO3 is susceptible to Cache Flooding
TYPO3-CORE-SA-2011-002: Potential SQL injection vulnerability in TYPO3 Core
It has been discovered that the TYPO3 prepared statement database API allows SQL Injections.
TYPO3-EXT-SA-2011-009: Several Vulnerabilities in extension MailformPlus (th_mailformplus)
Several vulnerabilities have been found in the following third-party TYPO3 extension: th_mailformplus