Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.4.9 vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2011-4628
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to bypass authentication mechanisms in the backend through a crafted request.
Typo3 Typo3
490
VMScore
CVE-2011-4902
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to delete arbitrary files on the webserver.
Typo3 Typo3
445
VMScore
CVE-2012-1607
The Command Line Interface (CLI) script in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to obtain the database name via a direct request.
Typo3 Typo3 4.4.13
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.4.11
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.0
Typo3 Typo3 4.4.9
Typo3 Typo3 4.4
Typo3 Typo3 4.4.8
Typo3 Typo3 4.4.10
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.12
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.7
445
VMScore
CVE-2012-1608
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 up to and including 4.4.13, 4.5.0 up to and including 4.5.13, 4.6.0 up to and including 4.6.6, 4.7, and 6.0 allows remote malicious users to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web scri...
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.12
Typo3 Typo3 4.6.6
Typo3 Typo3 4.6.3
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.13
Typo3 Typo3 4.4.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.6.0
Typo3 Typo3 4.4.11
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.6
Typo3 Typo3 6.0
Typo3 Typo3 4.4.1
Typo3 Typo3 4.5.0
Typo3 Typo3 4.6.5
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
383
VMScore
CVE-2011-4626
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.
Typo3 Typo3
383
VMScore
CVE-2011-4903
Cross-site Scripting (XSS) in TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the RemoveXSS function.
Typo3 Typo3
383
VMScore
CVE-2012-2112
Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x prior to 4.4.15, 4.5.x prior to 4.5.15, 4.6.x prior to 4.6.8, and 4.7 allows remote malicious users to inject arbitrary web script or HTML via exception messages.
Typo3 Typo3 4.4.14
Typo3 Typo3 4.4.13
Typo3 Typo3 4.4.4
Typo3 Typo3 4.4.5
Typo3 Typo3 4.4.11
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.4.6
Typo3 Typo3 4.4.7
Typo3 Typo3 4.4.0
Typo3 Typo3 4.4.9
Typo3 Typo3 4.4.8
Typo3 Typo3 4.4.10
Typo3 Typo3 4.4.3
Typo3 Typo3 4.4.12
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.9
Typo3 Typo3 4.5.12
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.13
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.14
356
VMScore
CVE-2011-4901
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows remote malicious users to extract arbitrary information from the TYPO3 database.
Typo3 Typo3
356
VMScore
CVE-2011-4627
TYPO3 prior to 4.3.12, 4.4.x prior to 4.4.9, and 4.5.x prior to 4.5.4 allows Information Disclosure on the backend.
Typo3 Typo3
356
VMScore
CVE-2011-4904
TYPO3 prior to 4.4.9 and 4.5.x prior to 4.5.4 does not apply proper access control on ExtDirect calls which allows remote malicious users to retrieve ExtDirect endpoint services.
Typo3 Typo3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6280
CVE-2024-5346
CVE-2024-30078
CVE-2022-45803
CVE-2024-36886
SQL
CVE-2024-24553
IMAP
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »