Typo3 Typo3.Cms vulnerabilities
16 known vulnerabilities affecting typo3/typo3.cms.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM11LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-32768MEDIUMCVSS 6.1v>= 7.0.0, < 7.6.53v>= 8.0.0, < 8.7.42+3 more2021-08-10
CVE-2021-32768 [MEDIUM] CWE-79 CVE-2021-32768: TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affec
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site scripting. Corresponding rendering instructions via TypoScript functionality HTML
cvelistv5nvd
CVE-2021-32669MEDIUMCVSS 5.4v>= 9.0.0, < 9.5.29v>= 10.0.0, < 10.4.18+1 more2021-07-20
CVE-2021-32669 [MEDIUM] CWE-79 CVE-2021-32669: TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When settings for _backend layouts_ are not properly encoded, the corresponding grid view is vulnerable to persistent cross-site scripting. A valid backend user ac
cvelistv5nvd
CVE-2021-32767MEDIUMCVSS 6.5v>= 9.0.0, < 9.5.28v>= 10.0.0, < 10.4.18+1 more2021-07-20
CVE-2021-32767 [MEDIUM] CWE-532 CVE-2021-32767: TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 1
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log level debug, which is not the default configuration. TYPO3 versions 9.5.28, 10.4.18, 11.3.1 contain a patch for thi
cvelistv5nvd
CVE-2021-32667MEDIUMCVSS 5.4v>= 9.0.0, < 9.5.29v>= 10.0.0, < 10.4.18+1 more2021-07-20
CVE-2021-32667 [MEDIUM] CWE-79 CVE-2021-32667: TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly encoded, corresponding page preview module (_Web>View_) is vulnerable to persistent cross-site scripting. A valid ba
cvelistv5nvd
CVE-2021-32668MEDIUMCVSS 4.8v>= 9.0.0, < 9.5.29v>= 10.0.0, < 10.4.18+1 more2021-07-20
CVE-2021-32668 [MEDIUM] CWE-79 CVE-2021-32668: TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the components _QueryGenerator_ and _QueryView_ are vulnerable to both reflected and persistent cross-site scripting.
cvelistv5nvd
CVE-2021-21339HIGHCVSS 7.5v>= 6.2.0, <= 6.2.56v>= 7.0.0, <= 7.6.50+4 more2021-03-23
CVE-2021-21339 [HIGH] CWE-312 CVE-2021-21339: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack
cvelistv5nvd
CVE-2021-21357HIGHCVSS 8.3v>= 8.0.0, <= 8.7.39v>= 9.0.0, <= 9.5.24+2 more2021-03-23
CVE-2021-21357 [HIGH] CWE-20 CVE-2021-21357: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input validation, attackers can by-pass restrictions of predefined options and submit arbitrary data in the Form Designer backend module of the Form Framework. In the default configuration of the Form Framework this
cvelistv5nvd
CVE-2021-21355HIGHCVSS 8.6v>= 8.0.0, <= 8.7.39v>= 9.0.0, <= 9.5.24+2 more2021-03-23
CVE-2021-21355 [HIGH] CWE-434 CVE-2021-21355: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htacces
cvelistv5nvd
CVE-2021-21340MEDIUMCVSS 5.4v>= 10.0.0, <= 10.4.13v>= 11.0.0, <= 11.1.02021-03-23
CVE-2021-21340 [MEDIUM] CWE-79 CVE-2021-21340: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 1
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 10.4
cvelistv5nvd
CVE-2021-21338MEDIUMCVSS 6.1v>= 6.2.0, <= 6.2.56v>= 7.0.0, <= 7.6.50+4 more2021-03-23
CVE-2021-21338 [MEDIUM] CWE-601 CVE-2021-21338: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and conducting phishing attacks. No authentication is required in order to exp
cvelistv5nvd
CVE-2021-21358MEDIUMCVSS 5.4v>= 10.2.0, <= 10.4.13v>= 11.0.0, <= 11.1.02021-03-23
CVE-2021-21358 [MEDIUM] CWE-79 CVE-2021-21358: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 1
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the form module is needed to exploit this vulnerability. This is fixed in versio
cvelistv5nvd
CVE-2021-21370MEDIUMCVSS 5.4v>= 7.0.0, <= 7.6.50v>= 8.0.0, <= 8.7.39+3 more2021-03-23
CVE-2021-21370 [MEDIUM] CWE-79 CVE-2021-21370: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulner
cvelistv5nvd
CVE-2021-21359MEDIUMCVSS 5.9v>= 9.0.0, <= 9.5.24v>= 10.0.0, <= 10.4.13+1 more2021-03-23
CVE-2021-21359 [MEDIUM] CWE-674 Denial of Service in Page Error Handling
Denial of Service in Page Error Handling
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impac
cvelistv5
CVE-2020-26228HIGHCVSS 7.5v>= 9.0.0, < 9.5.23v>= 10.0.0, < 10.4.102020-11-23
CVE-2020-26228 [HIGH] CWE-312 CVE-2020-26228: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL inj
cvelistv5nvd
CVE-2020-26227MEDIUMCVSS 6.1v>= 9.0.0, < 9.5.23v>= 10.0.0, < 10.4.102020-11-23
CVE-2020-26227 [MEDIUM] CWE-79 CVE-2020-26227: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
cvelistv5nvd
CVE-2020-26229LOWCVSS 3.7v>= 10.0.0, < 10.4.102020-11-23
CVE-2020-26229 [LOW] CWE-611 CVE-2020-26229: TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and b
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained
cvelistv5nvd