Vulnerabilities > Kitodo

DATE CVE VULNERABILITY TITLE RISK
2022-02-19 CVE-2022-24980 Server-Side Request Forgery (SSRF) vulnerability in Kitodo Kitodo.Presentation 3.1.2
An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3.
network
low complexity
kitodo CWE-918
7.5
2020-07-29 CVE-2020-16095 Cross-site Scripting vulnerability in Kitodo Kitodo.Presentation
The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
network
low complexity
kitodo CWE-79
6.1