Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.0.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-6690
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 up to and including 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlare...
Typo3 Typo3 4.0
Typo3 Typo3 4.0.1
Typo3 Typo3 3.7.0
Typo3 Typo3 3.8
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.3
1 EDB exploit
4
CVSSv2
CVE-2014-3945
The Authentication component in TYPO3 prior to 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote malicious users to bypass authentication and gain access to the backend by le...
Typo3 Typo3 4.0.0
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.10
Typo3 Typo3 4.0
Typo3 Typo3 4.0.12
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.9
Typo3 Typo3 4.1.0
Typo3 Typo3 4.1.15
Typo3 Typo3 4.1.3
Typo3 Typo3 4.1.8
Typo3 Typo3 4.2
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.16
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.9
Typo3 Typo3 4.3.13
Typo3 Typo3 4.3.2
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.9
7.5
CVSSv2
CVE-2009-0256
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 up to and including 4.0.9, 4.1.0 up to and including 4.1.7, and 4.2.0 up to and including 4.2.3 allows remote malicious users to hijack web sessions via unspecified vectors related to (1) frontend and (2)...
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.5
Typo3 Typo3 4.1.0
Typo3 Typo3 4.1.1
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.2
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.3
Typo3 Typo3 4.1.6
Typo3 Typo3 4.1.7
Typo3 Typo3 4.2.0
Typo3 Typo3 4.0
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.8
Typo3 Typo3 4.0.9
Typo3 Typo3 4.1.4
Typo3 Typo3 4.1.5
Typo3 Typo3 4.0.6
Typo3 Typo3 4.0.7
Typo3 Typo3 4.1.2
Typo3 Typo3 4.1.3
Typo3 Typo3 4.2.3
10
CVSSv2
CVE-2009-0258
The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 up to and including 4.0.9, 4.1.0 up to and including 4.1.7, and 4.2.0 up to and including 4.2.3 allows remote malicious users to execute arbitrary commands via a crafted filename containing shell metachara...
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.5
Typo3 Typo3 4.1.0
Typo3 Typo3 4.1.1
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.2
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.3
Typo3 Typo3 4.1.6
Typo3 Typo3 4.1.7
Typo3 Typo3 4.0
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.8
Typo3 Typo3 4.0.9
Typo3 Typo3 4.1.4
Typo3 Typo3 4.1.5
Typo3 Typo3 4.0.6
Typo3 Typo3 4.0.7
Typo3 Typo3 4.1.2
Typo3 Typo3 4.1.3
Typo3 Typo3 4.2.3
4.3
CVSSv2
CVE-2009-0257
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 up to and including 4.0.9, 4.1.0 up to and including 4.1.7, and 4.2.0 up to and including 4.2.3 allow remote malicious users to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files...
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.5
Typo3 Typo3 4.1.0
Typo3 Typo3 4.1.1
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.2
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.3
Typo3 Typo3 4.1.6
Typo3 Typo3 4.1.7
Typo3 Typo3 4.0
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.8
Typo3 Typo3 4.0.9
Typo3 Typo3 4.1.4
Typo3 Typo3 4.1.5
Typo3 Typo3 4.0.6
Typo3 Typo3 4.0.7
Typo3 Typo3 4.1.2
Typo3 Typo3 4.1.3
Typo3 Typo3 4.2.3
5
CVSSv2
CVE-2009-0255
The System extension Install tool in TYPO3 4.0.0 up to and including 4.0.9, 4.1.0 up to and including 4.1.7, and 4.2.0 up to and including 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for malicious users to crack the key.
Typo3 Typo3
Debian Debian Linux 4.0
7.5
CVSSv2
CVE-2021-38302
The Newsletter extension up to and including 4.0.0 for TYPO3 allows SQL Injection.
Newsletter Project Newsletter
4.3
CVSSv2
CVE-2017-5963
An issue exists in caddy (for TYPO3) prior to 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php"...
Caddy Project Caddy 2.1.4
Caddy Project Caddy 4.0.1
Caddy Project Caddy 4.0.3
Caddy Project Caddy 6.0.1
Caddy Project Caddy 6.1.0
Caddy Project Caddy 6.3.0
Caddy Project Caddy 6.0.2
Caddy Project Caddy 6.0.9
Caddy Project Caddy 6.0.12
Caddy Project Caddy 6.0.14
Caddy Project Caddy 2.1.5
Caddy Project Caddy 2.1.6
Caddy Project Caddy 3.0.0
Caddy Project Caddy 4.0.0
Caddy Project Caddy 6.3.3
Caddy Project Caddy 7.0.0
Caddy Project Caddy 7.1.0
Caddy Project Caddy 7.2.7
Caddy Project Caddy 4.0.2
Caddy Project Caddy 4.0.12
Caddy Project Caddy 6.2.1
Caddy Project Caddy 6.3.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
firmware
CVE-2006-4304
CVE-2024-32878
CVE-2024-31502
XSS
CVE-2024-3059
CVE-2024-33692
CVE-2024-3400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started