Vulnerabilities > Typo3 > Commerce Extension > 0.9.5

DATE CVE VULNERABILITY TITLE RISK
2010-07-28 CVE-2009-4963 Cross-Site Scripting vulnerability in Typo3 Commerce Extension
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
typo3 CWE-79
3.5
2008-12-17 CVE-2008-5609 SQL Injection vulnerability in Typo3 Commerce Extension
SQL injection vulnerability in the Commerce extension 0.9.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
typo3 CWE-89
7.5