typo3/cms-core Security Advisories for v8.7.32 (9)
- 
                        [HIGH] TYPO3 Install Tool vulnerable to Code ExecutionPKSA-prgj-sgzn-q6cs CVE-2024-22188 GHSA-5w2h-59j3-8x5w Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] Path Traversal in TYPO3 File Abstraction Layer StoragesPKSA-zz7z-6zsy-d2hc CVE-2023-30451 GHSA-w6x2-jg8h-p6mp Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [HIGH] TYPO3 vulnerable to Improper Access Control Persisting File Abstraction Layer Entities via Data HandlerPKSA-99mg-htb6-c272 CVE-2024-25121 GHSA-rj3x-wvc6-5j66 Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI SchemePKSA-h5xk-8nxx-znp4 CVE-2024-25120 GHSA-wf85-8hx9-gj7c Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 Install Tool vulnerable to Information Disclosure of Encryption KeyPKSA-d551-hdqh-5mmf CVE-2024-25119 GHSA-h47m-3f78-qp9g Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed PasswordsPKSA-jbhx-knzt-5y6m CVE-2024-25118 GHSA-38r2-5695-334w Affected version: =13.0.0|>=12.0.0,<=12.4.10|>=11.0.0,<=11.5.34|>=10.0.0,<=10.4.42|>=9.0.0,<=9.5.45|>=8.0.0,<=8.7.56 Reported by: 
 GitHub
- 
                        [MEDIUM] TYPO3-CORE-SA-2023-006: Weak Authentication in Session HandlingPKSA-jp7z-h3vv-yr4s CVE-2023-47127 GHSA-3vmm-7h4j-69rm Affected version: >=8.0.0,<8.7.55|>=9.0.0,<9.5.44|>=10.0.0,<10.4.41|>=11.0.0,<11.5.33|>=12.0.0,<12.4.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] TYPO3-CORE-SA-2020-011: Cleartext storage of session identifierPKSA-cqmn-5jhg-hqxx CVE-2020-26228 GHSA-954j-f27r-cj52 Affected version: >=10.0.0,<10.4.10|>=9.0.0,<9.5.23|>=8.7.0,<8.7.38 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] TYPO3-CORE-SA-2020-010: Cross-Site Scripting in Fluid view helpersPKSA-2ynr-pyxr-sckk CVE-2020-26227 GHSA-vqqx-jw6p-q3rf Affected version: >=10.0.0,<10.4.10|>=9.0.0,<9.5.23|>=8.7.0,<8.7.38 Reported by: 
 GitHub, FriendsOfPHP/security-advisories