CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2024-47047 MEDIUM

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure…

CVSS 5.5 EPSS 0.48% Sep 17, 2024
CVE-2024-45233 MEDIUM

An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insu…

CVSS 6.9 EPSS 0.38% Aug 28, 2024
CVE-2024-45232 MEDIUM

An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecu…

CVSS 6.9 EPSS 0.30% Aug 28, 2024
CVE-2022-44543 MEDIUM

The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a us…

CVSS 6.5 EPSS 0.60% Dec 12, 2023
CVE-2023-25014 HIGH

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationContr…

CVSS 8.6 EPSS 0.50% Feb 2, 2023
CVE-2023-25013 HIGH

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationContr…

CVSS 8.6 EPSS 0.50% Feb 2, 2023
CVE-2022-35628 CRITICAL

A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

CVSS 9.8 EPSS 26.82% Jul 12, 2022
CVE-2021-36787 MEDIUM

The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

CVSS 5.4 EPSS 1.33% Aug 13, 2021
CVE-2014-6292 MEDIUM

The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.

CVSS 6.8 EPSS 1.33% Oct 3, 2014
CVE-2008-2182 MEDIUM

Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 EPSS 1.29% May 13, 2008

Showing 1 to 10 CVEs · page 1