Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

typo3 — Vulnerabilities & Security Advisories 118

Browse all 118 CVE security advisories affecting typo3. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TYPO3 is an open-source enterprise content management system primarily designed for large-scale websites and complex digital platforms. Historically, its extensive feature set and modular architecture have introduced a significant attack surface, resulting in 118 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or improper access controls within extensions. While the core framework has seen improved security practices in recent versions, legacy installations remain particularly susceptible to exploitation. Notable incidents have frequently involved unpatched third-party extensions rather than core flaws, highlighting the critical importance of rigorous extension auditing. Security advisories are regularly issued by the TYPO3 Security Team, urging administrators to maintain strict update protocols to mitigate these persistent risks associated with its broad ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2021-21357 Broken Access Control in Form Framework — TYPO3.CMSCWE-20 8.3 High2021-03-23
CVE-2021-21358 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form — TYPO3.CMSCWE-79 5.4 Medium2021-03-23
CVE-2021-21338 Open Redirection in Login Handling — TYPO3.CMSCWE-601 4.7 Medium2021-03-23
CVE-2020-26229 XML External Entity in Dashboard Widget — TYPO3.CMSCWE-611 3.7 Low2020-11-23
CVE-2020-26228 Cleartext storage of session identifier — TYPO3.CMSCWE-312 8.1 High2020-11-23
CVE-2020-26227 Cross-Site Scripting in Fluid view helpers — TYPO3.CMSCWE-79 6.1 Medium2020-11-23
CVE-2020-26216 Cross-Site Scripting in TYPO3 Fluid — FluidCWE-79 8.0 High2020-11-17
CVE-2020-15241 Cross-Site Scripting in TYPO3 Fluid Engine — FluidCWE-601 4.7 Medium2020-10-08
CVE-2020-15098 Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS — TYPO3 CMSCWE-325 8.8 High2020-07-29
CVE-2020-15099 Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS — TYPO3 CMSCWE-200 8.1 High2020-07-29
CVE-2020-11069 Cross-Site Request Forgery in TYPO3 CMS — TYPO3 CMSCWE-352 8.0 High2020-05-13
CVE-2020-11067 Deserialization of Untrusted Data in TYPO3 CMS — TYPO3 CMSCWE-502 8.8 High2020-05-13
CVE-2020-11066 Improperly Controlled Modification of Dynamically-Determined Object Attributes in TYPO3 CMS — TYPO3 CMSCWE-915 8.7 High2020-05-13
CVE-2020-11065 Cross-Site Scripting in TYPO3 CMS — TYPO3 CMSCWE-79 5.4 Medium2020-05-13
CVE-2020-11064 Cross-Site Scripting in TYPO3 CMS — TYPO3 CMSCWE-79 5.4 Medium2020-05-13
CVE-2020-11063 Observable Response Discrepancy in TYPO3 CMS — TYPO3 CMSCWE-204 3.7 Low2020-05-13
CVE-2011-4904 TYPO3 输入验证错误漏洞 — TYPO3 4.3 -2019-11-06
CVE-2011-4903 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06
CVE-2011-4902 TYPO3 输入验证错误漏洞 — TYPO3 6.5 -2019-11-06
CVE-2011-4901 TYPO3 信息泄露漏洞 — TYPO3 6.5 -2019-11-06
CVE-2011-4900 TYPO3 信息泄露漏洞 — TYPO3 6.5 -2019-11-06
CVE-2011-4632 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06
CVE-2011-4631 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06
CVE-2011-4630 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06
CVE-2011-4629 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06
CVE-2011-4628 TYPO3 授权问题漏洞 — TYPO3 9.8 -2019-11-06
CVE-2011-4627 TYPO3 信息泄露漏洞 — TYPO3 6.5 -2019-11-06
CVE-2011-4626 TYPO3 跨站脚本漏洞 — TYPO3 5.4 -2019-11-06

This page lists every published CVE security advisory associated with typo3. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.