Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.5 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2011-4614
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x prior to 4.5.9, 4.6.x prior to 4.6.2, and development versions of 4.7 allows remote malicious users to execute arbitrary PHP code via a URL in th...
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5
Typo3 Typo3 4.5.7
Typo3 Typo3 4.6
Typo3 Typo3 4.6.1
1 EDB exploit
3.5
CVSSv2
CVE-2012-3528
Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x prior to 4.5.19, 4.6.x prior to 4.6.12 and 4.7.x prior to 4.7.4 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.18
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.1
Typo3 Typo3 4.6.1
Typo3 Typo3 4.6
4.3
CVSSv2
CVE-2012-3531
Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x prior to 4.5.19, 4.6.x prior to 4.6.12 and 4.7.x prior to 4.7.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.18
Typo3 Typo3 4.6.5
Typo3 Typo3 4.6.6
3.5
CVSSv2
CVE-2012-3529
The configuration module in the backend in TYPO3 4.5.x prior to 4.5.19, 4.6.x prior to 4.6.12 and 4.7.x prior to 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.18
Typo3 Typo3 4.6.6
Typo3 Typo3 4.6.1
4.3
CVSSv2
CVE-2012-3530
Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x prior to 4.5.19, 4.6.x prior to 4.6.12 and 4.7.x prior to 4.7.4 allows remote malicious users to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript events.
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.18
Typo3 Typo3 4.6.6
Typo3 Typo3 4.6.1
5
CVSSv2
CVE-2012-1607
The Command Line Interface (CLI) script in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to obtain the database name via a direct request.
Typo3 Typo3 4.4.10
Typo3 Typo3 4.4.12
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.0
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.8
Typo3 Typo3 4.4
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.9
Typo3 Typo3 4.4.13
Typo3 Typo3 4.4.11
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.5
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
6.5
CVSSv2
CVE-2012-6144
SQL injection vulnerability in the Backend History module in TYPO3 4.5.x prior to 4.5.21, 4.6.x prior to 4.6.14, and 4.7.x prior to 4.7.6 allows remote authenticated backend users to execute arbitrary SQL commands via unspecified vectors.
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.20
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.18
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.19
Typo3 Typo3 4.5.16
3.5
CVSSv2
CVE-2012-6145
Cross-site scripting (XSS) vulnerability in the Backend History module in TYPO3 4.5.x prior to 4.5.21, 4.6.x prior to 4.6.14, and 4.7.x prior to 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.18
Typo3 Typo3 4.5.19
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.20
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.13
3.5
CVSSv2
CVE-2012-6147
Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x prior to 4.5.21, 4.6.x prior to 4.6.14, and 4.7.x prior to 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.20
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.15
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.19
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.18
3.5
CVSSv2
CVE-2012-6148
Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x prior to 4.5.21, 4.6.x prior to 4.6.14, and 4.7.x prior to 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.18
Typo3 Typo3 4.5.19
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5.10
Typo3 Typo3 4.5.2
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.20
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5
Typo3 Typo3 4.5.11
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.17
Typo3 Typo3 4.5.14
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.0
Typo3 Typo3 4.5.16
Typo3 Typo3 4.5.15
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »