Vulnerabilities > Typo3

DATE CVE VULNERABILITY TITLE RISK
2016-01-08 CVE-2015-8757 Cross-site Scripting vulnerability in Typo3
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.
network
typo3 CWE-79
4.3
2016-01-08 CVE-2015-8756 Cross-site Scripting vulnerability in Typo3
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.
network
typo3 CWE-79
3.5
2016-01-08 CVE-2015-8755 Cross-site Scripting vulnerability in Typo3
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
network
typo3 CWE-79
3.5
2015-09-16 CVE-2015-5956 Cross-site Scripting vulnerability in Typo3
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.
network
typo3 CWE-79
3.5
2015-04-01 CVE-2015-2821 Permissions, Privileges, and Access Controls vulnerability in Typo3 Neos
TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.
network
low complexity
typo3 CWE-264
6.5
2015-02-23 CVE-2015-2047 Improper Authentication vulnerability in multiple products
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.
network
high complexity
typo3 debian CWE-287
2.6
2015-01-04 CVE-2014-9509 Improper Input Validation vulnerability in Typo3
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.
network
low complexity
typo3 CWE-20
7.5
2015-01-04 CVE-2014-9508 Link Following vulnerability in Typo3
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.
network
typo3 CWE-59
4.3
2014-06-04 CVE-2014-3949 Cross-Site Scripting vulnerability in JO Hasenau Gridelements
Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
3.5
2014-06-04 CVE-2014-3948 Cross-Site Scripting vulnerability in Alex Kellner Powermail
Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension before 1.6.11 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3