Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.4.1 vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2010-3666
TYPO3 prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 contains insecure randomness in the uniqid function.
Typo3 Typo3
5.3
CVSSv3
CVE-2010-3667
TYPO3 prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 allows Spam Abuse in the native form content element.
Typo3 Typo3
8.8
CVSSv3
CVE-2010-3663
TYPO3 prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote malicious users to execute arbitrary code on the backend.
Typo3 Typo3
5.4
CVSSv3
CVE-2010-3660
TYPO3 prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 allows XSS on the backend.
Typo3 Typo3
6.1
CVSSv3
CVE-2010-3661
TYPO3 prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 allows Open Redirection on the backend.
Typo3 Typo3
5.4
CVSSv3
CVE-2010-3659
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x prior to 4.1.14, 4.2.x prior to 4.2.13, 4.3.x prior to 4.3.4, and 4.4.x prior to 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extensio...
Typo3 Typo3 4.2.10
Typo3 Typo3 4.1.11
Typo3 Typo3 4.1.1
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.11
Typo3 Typo3 4.1.8
Typo3 Typo3 4.1.6
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.8
Typo3 Typo3 4.1.12
Typo3 Typo3 4.2.3
Typo3 Typo3 4.1.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.1.7
Typo3 Typo3 4.3.2
Typo3 Typo3 4.1.0
Typo3 Typo3 4.1.13
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.0
Typo3 Typo3 4.1.9
NA
CVE-2015-2047
The rsaauth extension in TYPO3 4.3.0 up to and including 4.3.14, 4.4.0 up to and including 4.4.15, 4.5.0 up to and including 4.5.39, and 4.6.0 up to and including 4.6.18, when configured for the frontend, allows remote malicious users to bypass authentication via a password that ...
Typo3 Typo3 4.3.6
Typo3 Typo3 4.5.30
Typo3 Typo3 4.5.3
Typo3 Typo3 4.6.16
Typo3 Typo3 4.5.27
Typo3 Typo3 4.3.5
Typo3 Typo3 4.5.9
Typo3 Typo3 4.3.8
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.24
Typo3 Typo3 4.6.6
Typo3 Typo3 4.6.3
Typo3 Typo3 4.6.13
Typo3 Typo3 4.5.32
Typo3 Typo3 4.3.7
Typo3 Typo3 4.3.14
Typo3 Typo3 4.4.14
Typo3 Typo3 4.5.15
Typo3 Typo3 4.6.12
Typo3 Typo3 4.5.35
Typo3 Typo3 4.6.8
Typo3 Typo3 4.5.38
NA
CVE-2014-3945
The Authentication component in TYPO3 prior to 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote malicious users to bypass authentication and gain access to the backend by le...
Typo3 Typo3 4.7.5
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.7.8
Typo3 Typo3 4.1.11
Typo3 Typo3 4.5.30
Typo3 Typo3 4.1.1
Typo3 Typo3 4.7.17
Typo3 Typo3 4.5.3
Typo3 Typo3 4.6.16
Typo3 Typo3 4.5.27
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.5.9
Typo3 Typo3 4.3.8
Typo3 Typo3 4.5.12
Typo3 Typo3 6.0.11
Typo3 Typo3 6.0.1
Typo3 Typo3 4.2.4
Typo3 Typo3 4.1
Typo3 Typo3 4.5.24
Typo3 Typo3 6.1.3
NA
CVE-2012-1607
The Command Line Interface (CLI) script in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to obtain the database name via a direct request.
Typo3 Typo3 4.4.13
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.4.11
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.0
Typo3 Typo3 4.4.9
Typo3 Typo3 4.4
Typo3 Typo3 4.4.8
Typo3 Typo3 4.4.10
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.12
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.7
NA
CVE-2012-1608
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web scri...
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.12
Typo3 Typo3 4.6.6
Typo3 Typo3 4.6.3
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.13
Typo3 Typo3 4.4.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.6.0
Typo3 Typo3 4.4.11
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.6
Typo3 Typo3 6.0
Typo3 Typo3 4.4.1
Typo3 Typo3 4.5.0
Typo3 Typo3 4.6.5
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »