Vulnerability Name CVE Severity
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-21358) CVE-2021-21358
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-21365) CVE-2021-21365
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-21370) CVE-2021-21370
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32667) CVE-2021-32667
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32668) CVE-2021-32668
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32669) CVE-2021-32669
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32768) CVE-2021-32768
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-31048) CVE-2022-31048
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-31049) CVE-2022-31049
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-36107) CVE-2022-36107
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-36108) CVE-2022-36108
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-24814) CVE-2023-24814
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-47125) CVE-2023-47125
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-34355) CVE-2024-34355
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-34356) CVE-2024-34356
TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-34357) CVE-2024-34357
TYPO3 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La Vulnerability (CVE-2022-23504) CVE-2022-23504
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2007-6381) CVE-2007-6381
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-3632) CVE-2009-3632
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-5103) CVE-2010-5103
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-6144) CVE-2012-6144
TYPO3 Inadequate Encryption Strength Vulnerability (CVE-2010-3670) CVE-2010-3670
TYPO3 Incorrect Authorization Vulnerability (CVE-2024-47780) CVE-2024-47780
TYPO3 Incorrect Authorization Vulnerability (CVE-2025-47937) CVE-2025-47937
TYPO3 Incorrect Authorization Vulnerability (CVE-2025-59020) CVE-2025-59020
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2021-32767) CVE-2021-32767
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2022-31047) CVE-2022-31047
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2024-55891) CVE-2024-55891
Typo3 Install Tool publicly accessible
TYPO3 Insufficient Entropy Vulnerability (CVE-2025-59015) CVE-2025-59015
TYPO3 Insufficient Session Expiration Vulnerability (CVE-2022-23502) CVE-2022-23502
TYPO3 Missing Authorization Vulnerability (CVE-2025-59021) CVE-2025-59021
TYPO3 Observable Discrepancy Vulnerability (CVE-2022-36105) CVE-2022-36105
TYPO3 Other Vulnerability (CVE-2006-0327) CVE-2006-0327
TYPO3 Other Vulnerability (CVE-2009-3630) CVE-2009-3630
TYPO3 Other Vulnerability (CVE-2012-1605) CVE-2012-1605
TYPO3 Other Vulnerability (CVE-2012-3530) CVE-2012-3530
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2717) CVE-2008-2717
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3717) CVE-2010-3717
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6146) CVE-2012-6146
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4320) CVE-2013-4320
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7073) CVE-2013-7073
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7081) CVE-2013-7081
TYPO3 Resource Management Errors Vulnerability (CVE-2013-1843) CVE-2013-1843
TYPO3 Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-47936) CVE-2025-47936
TYPO3 Session Fixation Vulnerability (CVE-2010-3671) CVE-2010-3671
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2025-47939) CVE-2025-47939
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3661) CVE-2010-3661
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3669) CVE-2010-3669
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-15241) CVE-2020-15241
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-21338) CVE-2021-21338
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-55892) CVE-2024-55892
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-59013) CVE-2025-59013
TYPO3 Use of Insufficiently Random Values Vulnerability (CVE-2010-3666) CVE-2010-3666
UAParser.js Other Vulnerability (CVE-2020-7793) CVE-2020-7793
UAParser.js Uncontrolled Resource Consumption Vulnerability (CVE-2020-7733) CVE-2020-7733
Unauthenticated OpenAI API Access
Unauthorized Access to a web app installer
Unchecked GraphQL Query Length: Potential Denial of Service Vulnerability
Undertow Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2021-3597) CVE-2021-3597
Undertow CVE-2022-2764 Vulnerability (CVE-2022-2764) CVE-2022-2764
Undertow Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7816) CVE-2014-7816
Undertow Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2018-1067) CVE-2018-1067
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2017-7559) CVE-2017-7559
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-10687) CVE-2020-10687
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-10719) CVE-2020-10719
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2021-20220) CVE-2021-20220
Undertow Incorrect Authorization Vulnerability (CVE-2017-12196) CVE-2017-12196
Unicode Transformation (Best-Fit Mapping)
Unprotected Apache NiFi API interface
Unprotected JSON file leaking secrets
Unprotected Kong Gateway Admin API interface
Unrestricted access to AnythingLLM API CVE-2024-6842
Unrestricted access to MLflow
Unrestricted access to NGINX+ API interface (read only)