Security Advisories
All Advisories
TYPO3-CORE-SA-2024-001: Path Traversal in TYPO3 File Abstraction Layer Storages
It has been discovered that TYPO3 CMS is susceptible to path traversal.
Read moreTYPO3-EXT-SA-2023-011: Configuration Injection in extension "Direct Mail" (direct_mail)
It has been discovered that the extension "Direct Mail" (direct_mail) is susceptible to Configuration Injection.
TYPO3-EXT-SA-2023-010: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2023-009: Insecure Direct Object Reference in extension "Content Consent" (content_consent)
It has been discovered that the extension "Content Consent" (content_consent) is susceptible to Insecure Direct Object Reference.
TYPO3-CORE-SA-2023-007: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2023-006: Weak Authentication in Session Handling
It has been discovered that TYPO3 CMS is susceptible to weak authentication.
TYPO3-CORE-SA-2023-005: Information Disclosure in Install Tool
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2023-008: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2023-007: Broken Access Control in extension "hCaptcha for EXT:form" (hcaptcha)
It has been discovered that the extension "hCaptcha for EXT:form" (hcaptcha) is susceptible to Broken Access Control.
TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.