Skip to main navigation Skip to main content Skip to page footer

Security Advisories

All Advisories

Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.

Subscribe to TYPO3 security advisories 

TYPO3-20050812-1: TYPO3 Security Bulletin

Remote exploitation of an input validation vulnerability in AWStats allows remote attackers to execute arbitrary commands. Successful exploitation results in the execution of arbitrary commands with permissions of the web service. This may compromise systems using extensions providing AWStats.

Read more

TYPO3-20050725-1: TYPO3 Security Bulletin

A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.

TYPO3-20050307-1: TYPO3 Security Bulletin

Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong receipient. Thus, spam mails may be sent from a remote site.

TYPO3-20050304-1: TYPO3 Security Bulletin

An issue has been reported where a bug in the "cmw_linklist" extension allows SQL injection attacks. In specific situations, a remote offender can cause malicious database operations.