Security Advisories
All Advisories
TYPO3-EXT-SA-2013-003: SQL Injection vulnerability in extension CoolURI (cooluri)
It has been discovered that the extension "CoolURI" (cooluri) is vulnerable to SQL Injection.
Read moreTYPO3-EXT-SA-2013-002: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: attacalendar, attacpetition, eu_subscribe, exinit_job_offer, fefilebrowser, js_css_optimizer, kk_csv2table, lonewsseo, mn_mysql2json, news_search, tipafriend_plus, twitter_auth, sofortueberweisung2commerce, sys_messages
TYPO3-EXT-SA-2013-001: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: news, onetimeaccount, phpunit, div2007, t3mootools, t3jquery, oneclicklogin
TYPO3-EXT-SA-2012-013: Several Vulnerabilities in extension commerce (commerce)
It has been discovered that the extension commerce (commerce) is vulnerable to Cross Site Scripting.
TYPO3-CORE-SA-2012-005: Several Vulnerabilities in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to SQL Injection, Information Disclosure and Cross-Site Scripting
TYPO3-EXT-SA-2012-012: Several Vulnerabilities in extension Formhandler (formhandler)
It has been discovered that the extension Formhandler (formhandler) is vulnerable to SQL-Injection and Cross-Site Scripting.
TYPO3-CORE-SA-2012-004: Several Vulnerabilities in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Cross-Site Scripting, Information Disclosure, Insecure Unserialize leading to Arbitrary Code Execution
TYPO3-EXT-SA-2012-011: Cross-site scripting vulnerability in extension powermail for TYPO3 (powermail)
It has been discovered that the extension "powermail" (powermail) is vulnerable to Cross-Site Scripting, SQL Injection and Arbitrary Code Execution.
TYPO3-CORE-SA-2012-003: Cross-Site Scripting Vulnerability in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Cross-Site Scripting.
TYPO3-EXT-SA-2012-010: Cross-site scripting vulnerability in extension Seminars (seminars)
It has been discovered that the extension "Seminars" (seminars) is vulnerable to cross-site scripting.