Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.5.4 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2011-4903
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the RemoveXSS function.
Typo3 Typo3
4
CVSSv2
CVE-2011-4901
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to extract arbitrary information from the TYPO3 database.
Typo3 Typo3
4.3
CVSSv2
CVE-2011-4626
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.
Typo3 Typo3
4
CVSSv2
CVE-2011-4627
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows Information Disclosure on the backend.
Typo3 Typo3
7.5
CVSSv2
CVE-2011-4628
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to bypass authentication mechanisms in the backend through a crafted request.
Typo3 Typo3
3.5
CVSSv2
CVE-2011-4629
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the admin panel.
Typo3 Typo3
3.5
CVSSv2
CVE-2011-4630
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the browse_links wizard.
Typo3 Typo3
3.5
CVSSv2
CVE-2011-4631
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the system extension recycler.
Typo3 Typo3
3.5
CVSSv2
CVE-2011-4632
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the tcemain flash message.
Typo3 Typo3
4
CVSSv2
CVE-2011-4900
TYPO3 prior to 4.5.4 allows Information Disclosure in the backend.
Typo3 Typo3
Debian Debian Linux 5.0
Debian Debian Linux 6.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »