typo3/cms-core Security Advisories for v8.7.16 (44)
- 
                        [MEDIUM] TYPO3 Cross-Site Scripting in Form Framework validation handlingPKSA-yj7d-v8zz-m6nq GHSA-95qm-3xp7-vfj5 Affected version: >=9.0.0,<9.5.12|>=8.0.0,<8.7.30|>=10.0.0,<10.2.1 Reported by: 
 GitHub
- 
                        [HIGH] TYPO3 Install Tool vulnerable to Code ExecutionPKSA-prgj-sgzn-q6cs CVE-2024-22188 GHSA-5w2h-59j3-8x5w Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] Path Traversal in TYPO3 File Abstraction Layer StoragesPKSA-zz7z-6zsy-d2hc CVE-2023-30451 GHSA-w6x2-jg8h-p6mp Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [HIGH] TYPO3 vulnerable to Improper Access Control Persisting File Abstraction Layer Entities via Data HandlerPKSA-99mg-htb6-c272 CVE-2024-25121 GHSA-rj3x-wvc6-5j66 Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI SchemePKSA-h5xk-8nxx-znp4 CVE-2024-25120 GHSA-wf85-8hx9-gj7c Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 Install Tool vulnerable to Information Disclosure of Encryption KeyPKSA-d551-hdqh-5mmf CVE-2024-25119 GHSA-h47m-3f78-qp9g Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed PasswordsPKSA-jbhx-knzt-5y6m CVE-2024-25118 GHSA-38r2-5695-334w Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3-CORE-SA-2023-006: Weak Authentication in Session HandlingPKSA-jp7z-h3vv-yr4s CVE-2023-47127 GHSA-3vmm-7h4j-69rm Affected version: >=8.0.0,<8.7.55|>=9.0.0,<9.5.44|>=10.0.0,<10.4.41|>=11.0.0,<11.5.33|>=12.0.0,<12.4.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] TYPO3-CORE-SA-2020-011: Cleartext storage of session identifierPKSA-cqmn-5jhg-hqxx CVE-2020-26228 GHSA-954j-f27r-cj52 Affected version: >=10.0.0,<10.4.10|>=9.0.0,<9.5.23|>=8.7.0,<8.7.38 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] TYPO3-CORE-SA-2020-010: Cross-Site Scripting in Fluid view helpersPKSA-2ynr-pyxr-sckk CVE-2020-26227 GHSA-vqqx-jw6p-q3rf Affected version: >=10.0.0,<10.4.10|>=9.0.0,<9.5.23|>=8.7.0,<8.7.38 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Insecure Deserialization in Query Generator & Query ViewPKSA-2xbd-k6f8-vc7m CVE-2019-19849 GHSA-rcgc-4xfc-564v Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] SQL Injection in low-level Query GeneratorPKSA-gt1g-9dsw-fhqp CVE-2019-19850 GHSA-59pj-7mjh-4465 Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Directory Traversal on ZIP extractionPKSA-jydd-ptqz-cc3y CVE-2019-19848 GHSA-77p4-wfr8-977w Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Cross-Site Scripting in Form Framework validation handlingPKSA-4jxn-z7kk-hs67 GHSA-rxc9-f2x6-qh4w Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Link HandlingPKSA-138z-v62j-p84r GHSA-4459-qrcc-vfcf Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Possible Insecure Deserialization in Extbase Request HandlingPKSA-ngtt-95zk-116b GHSA-f9hr-7cfq-mjg2 Affected version: >=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Cross-Site Scripting in Filelist ModulePKSA-kgft-67y3-84tv GHSA-82vp-jr39-4j2j Affected version: >=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Insecure Deserialization in TYPO3 CMSPKSA-s5jg-xrdb-kcbj CVE-2019-12747 GHSA-86hp-xrhj-fhpq Affected version: >=8.0.0,<8.7.27|>=9.0.0,<9.5.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Link HandlingPKSA-v9y4-y7z6-sjjg CVE-2019-12748 GHSA-r6fv-56gp-j3r4 Affected version: >=8.0.0,<8.7.27|>=9.0.0,<9.5.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Security Misconfiguration in Frontend Session HandlingPKSA-tdw8-rcwc-259v GHSA-45wj-jv2h-jwrf Affected version: >=8.0.0,<8.7.27|>=9.0.0,<9.5.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Arbitrary Code Execution and Cross-Site Scripting in Backend APIPKSA-f5jr-dg29-ng7s GHSA-22q7-cg4r-p9mx Affected version: >=8.0.0,<8.7.27|>=9.0.0,<9.5.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Information Disclosure in Backend User InterfacePKSA-xxc6-f4fc-bhvm GHSA-5h5v-m596-r6rf Affected version: >=8.0.0,<8.7.27|>=9.0.0,<9.5.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Possible Arbitrary Code Execution in Image ProcessingPKSA-zhxh-zqgh-5btz CVE-2019-11832 GHSA-3w4h-r27h-4r2w Affected version: >=8.0.0,<8.7.25|>=9.0.0,<9.5.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Fluid EnginePKSA-1rbp-fbhh-b1cd CVE-2020-15241 GHSA-7733-hjv6-4h47 Affected version: >=8.0.0,<8.7.25|>=9.0.0,<9.5.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Security Misconfiguration in User Session HandlingPKSA-44gr-w8s1-1nzt GHSA-g776-759r-pf6x Affected version: >=8.0.0,<8.7.25|>=9.0.0,<9.5.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Bootstrap CSS toolkitPKSA-6rbt-6s1d-gvry CVE-2018-14041 GHSA-pj7m-g53m-7638 Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Arbitrary Code Execution via File List ModulePKSA-fnjs-nj4b-mz65 GHSA-cc97-g92w-jm65 Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Security Misconfiguration for Backend User AccountsPKSA-jktp-yswk-rrww GHSA-hjx5-v9xg-7h25 Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Broken Access Control in Localization HandlingPKSA-xy95-nkpr-w5rm GHSA-xmgr-jff3-fcfv Affected version: >=8.0.0,<8.7.23 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Information Disclosure of Installed ExtensionsPKSA-t2bp-d8b3-sc74 GHSA-p2h4-7fp3-cmh8 Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Form FrameworkPKSA-3886-d5zt-qwrh GHSA-rv8r-8mh5-5376 Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Fluid ViewHelpersPKSA-ctc9-m9tc-zx87 GHSA-6xwf-7rfm-4gwc Affected version: >=8.0.0,<8.7.23|>=9.0.0,<9.5.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in CKEditorPKSA-5y7r-7h1g-qrym CVE-2018-17960 GHSA-g68x-vvqq-pvw3 Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Information Disclosure in Install ToolPKSA-sntp-fryn-mxq8 GHSA-wg8h-gxf4-g4gh Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Denial of Service in Online Media Asset HandlingPKSA-rvt7-wnc1-w2gd GHSA-8c25-vj2w-p72j Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Cross-Site Scripting in Online Media Asset RenderingPKSA-qszd-7zv5-3hkx GHSA-66c2-7g4p-wx4p Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Cross-Site Scripting in Backend Modal ComponentPKSA-yzt1-7625-ng3j GHSA-ppvg-hw62-6ph9 Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Denial of Service in Frontend Record RegistrationPKSA-q5ym-2n81-pfr3 GHSA-29m4-mx89-3mjg Affected version: >=8.0.0,<8.7.21 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Security Misconfiguration in Install Tool CookiePKSA-2q76-3mvw-8hk3 GHSA-9rx9-7fmh-gj3g Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Cross-Site Scripting in Frontend User LoginPKSA-8d3v-z4d4-n11g GHSA-x428-565f-8xj2 Affected version: >=8.0.0,<8.7.21|>=9.0.0,<9.5.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Insecure Deserialization in TYPO3 CMSPKSA-nx6h-6z7h-64pg GHSA-x4rj-f7m6-42c3 Affected version: >=8.5.0,<8.7.17|>=9.0.0,<9.3.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Privilege Escalation & SQL Injection in TYPO3 CMSPKSA-jndc-1hrg-s597 GHSA-76r3-m635-p3vc Affected version: >=8.5.0,<8.7.17|>=9.0.0,<9.3.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Insecure Deserialization & Arbitrary Code Execution in TYPO3 CMSPKSA-53xp-pxrc-sbvb GHSA-wvvp-jwf5-qcpc Affected version: >=8.0.0,<8.7.17|>=9.0.0,<9.3.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Authentication Bypass in TYPO3 CMSPKSA-f4p7-n9ff-b1y3 GHSA-4ppr-jw47-9qm5 Affected version: >=8.0.0,<8.7.17|>=9.0.0,<9.3.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories