Loading product vulnerabilities…
Total
4
Critical
1
High
1
Medium
2
CISA KEV
0
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.