| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2021-41114 | HTTP Host Header Injection in Request Handling in Typo3 | TYPO3 | typo3 | Medium | 4.8 | 2021-10-05 17:15:11 | Deep Dive |
| CVE-2021-32768 | Cross-Site Scripting via Rich-Text Content | TYPO3 | TYPO3.CMS | Medium | 6.1 | 2021-08-10 16:30:11 | Deep Dive |
| CVE-2021-32767 | Information Disclosure in User Authentication | TYPO3 | TYPO3.CMS | Medium | 5.3 | 2021-07-20 16:00:11 | Deep Dive |
| CVE-2021-32669 | Cross-Site Scripting in Backend Grid View | TYPO3 | TYPO3.CMS | Medium | 6.4 | 2021-07-20 15:35:11 | Deep Dive |
| CVE-2021-32668 | Cross-Site Scripting in Query Generator & Query View | TYPO3 | TYPO3.CMS | Medium | 6.4 | 2021-07-20 14:45:13 | Deep Dive |
| CVE-2021-32667 | Cross-Site Scripting in Page Preview | TYPO3 | TYPO3.CMS | Medium | 6.4 | 2021-07-20 14:40:11 | Deep Dive |
| CVE-2021-21359 | Denial of Service in Page Error Handling | TYPO3 | TYPO3.CMS | Medium | 5.9 | 2021-03-23 01:55:19 | Deep Dive |
| CVE-2021-21370 | Cross-Site Scripting in Content Preview (CType menu) | TYPO3 | TYPO3.CMS | Medium | 5.4 | 2021-03-23 01:55:12 | Deep Dive |
| CVE-2021-21339 | Cleartext storage of session identifier | TYPO3 | TYPO3.CMS | Medium | 5.9 | 2021-03-23 01:50:40 | Deep Dive |
| CVE-2021-21340 | Cross-Site Scripting in Content Preview | TYPO3 | TYPO3.CMS | Medium | 5.4 | 2021-03-23 01:50:34 | Deep Dive |
| CVE-2021-21355 | Unrestricted File Upload in Form Framework | TYPO3 | TYPO3.CMS | High | 8.6 | 2021-03-23 01:50:29 | Deep Dive |
| CVE-2021-21357 | Broken Access Control in Form Framework | TYPO3 | TYPO3.CMS | High | 8.3 | 2021-03-23 01:50:23 | Deep Dive |
| CVE-2021-21358 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form | TYPO3 | TYPO3.CMS | Medium | 5.4 | 2021-03-23 01:50:16 | Deep Dive |
| CVE-2021-21338 | Open Redirection in Login Handling | TYPO3 | TYPO3.CMS | Medium | 4.7 | 2021-03-23 01:45:14 | Deep Dive |
| CVE-2020-26229 | XML External Entity in Dashboard Widget | TYPO3 | TYPO3.CMS | Low | 3.7 | 2020-11-23 21:15:18 | Deep Dive |
| CVE-2020-26228 | Cleartext storage of session identifier | TYPO3 | TYPO3.CMS | High | 8.1 | 2020-11-23 21:10:16 | Deep Dive |
| CVE-2020-26227 | Cross-Site Scripting in Fluid view helpers | TYPO3 | TYPO3.CMS | Medium | 6.1 | 2020-11-23 21:05:18 | Deep Dive |
| CVE-2020-26216 | Cross-Site Scripting in TYPO3 Fluid | TYPO3 | Fluid | High | 8.0 | 2020-11-17 20:45:20 | Deep Dive |
| CVE-2020-15241 | Cross-Site Scripting in TYPO3 Fluid Engine | TYPO3 | Fluid | Medium | 4.7 | 2020-10-08 20:15:17 | Deep Dive |
| CVE-2020-15098 | Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS | TYPO3 | TYPO3 CMS | High | 8.8 | 2020-07-29 16:15:25 | Deep Dive |