Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.4.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-5097
Cross-site scripting (XSS) vulnerability in the click enlarge functionality in TYPO3 4.3.x prior to 4.3.9 and 4.4.x prior to 4.4.5 when the caching framework is enabled, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.3.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.8
Typo3 Typo3 4.3.6
Typo3 Typo3 4.3.4
Typo3 Typo3 4.4
Typo3 Typo3 4.4.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.3.1
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.3
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.4
NA
CVE-2010-5101
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality.&q...
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.10
Typo3 Typo3 4.2.2
Typo3 Typo3 4.3.4
Typo3 Typo3 4.3.5
Typo3 Typo3 4.4.1
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.8
Typo3 Typo3 4.3.1
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.12
Typo3 Typo3 4.3.6
Typo3 Typo3 4.3.0
Typo3 Typo3 4.4.2
NA
CVE-2010-5102
Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote malicious users to write arbitrary files via unspecified vectors.
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.2
Typo3 Typo3 4.3.1
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.0
Typo3 Typo3 4.3.4
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.1
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.2
Typo3 Typo3 4.2.4
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.3
Typo3 Typo3 4.2.3
NA
CVE-2010-5103
SQL injection vulnerability in the list module in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.4
Typo3 Typo3 4.3.3
Typo3 Typo3 4.3.2
Typo3 Typo3 4.3.1
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2.11
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.8
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.10
Typo3 Typo3 4.2.2
Typo3 Typo3 4.3.4
Typo3 Typo3 4.3.5
Typo3 Typo3 4.2.7
NA
CVE-2010-5104
The escapeStrForLike method in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote malicious users to obtain sensitive information via wildc...
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.12
Typo3 Typo3 4.3.6
Typo3 Typo3 4.3.0
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.3
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.4
Typo3 Typo3 4.3.5
Typo3 Typo3 4.4.1
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2.4
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.8
Typo3 Typo3 4.3.1
NA
CVE-2010-5099
The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 does not properly filter file types, which allows remote malicious users to bypass intended access restrictions and access arb...
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.2
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.8
Typo3 Typo3 4.3.2
Typo3 Typo3 4.3.3
Typo3 Typo3 4.3.4
Typo3 Typo3 4.3.5
1 EDB exploit
NA
CVE-2010-5098
Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.13
Typo3 Typo3 4.3.3
Typo3 Typo3 4.3.4
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.1
Typo3 Typo3 4.2
Typo3 Typo3 4.2.2
Typo3 Typo3 4.2.10
Typo3 Typo3 4.2.11
Typo3 Typo3 4.3.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2.7
Typo3 Typo3 4.2.14
Typo3 Typo3 4.2.15
NA
CVE-2010-5100
Multiple cross-site scripting (XSS) vulnerabilities in the Install Tool in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.10
Typo3 Typo3 4.2.2
Typo3 Typo3 4.3.3
Typo3 Typo3 4.3.4
Typo3 Typo3 4.3.5
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.1
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.9
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.6
Typo3 Typo3 4.2
Typo3 Typo3 4.2.1
Typo3 Typo3 4.2.4
NA
CVE-2012-1606
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML ...
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.10
Typo3 Typo3 4.4.12
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.12
Typo3 Typo3 4.4.13
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.2
Typo3 Typo3 4.6.1
Typo3 Typo3 4.6.2
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.8
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.10
NA
CVE-2012-1608
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web scri...
Typo3 Typo3 4.4.0
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.3
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.6
Typo3 Typo3 4.6.5
Typo3 Typo3 4.6.6
Typo3 Typo3 4.7
Typo3 Typo3 6.0
Typo3 Typo3 4.4.5
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.12
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.9
Typo3 Typo3 4.6.2
Typo3 Typo3 4.6.4
Typo3 Typo3 4.4.8
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hardcoded
arbitrary code
CVE-2024-2404
CVE-2024-21111
CVE-2024-28627
CVE-2024-4073
information disclosure
CVE-2024-32780
CVE-2024-4040
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »