Vulnerabilities (CVE)

Filtered by vendor In2code Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44543 1 In2code 1 Femanager 2023-12-14 N/A 5.3 MEDIUM
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.
CVE-2022-35628 1 In2code 1 Living User Experience 2022-07-27 7.5 HIGH 9.8 CRITICAL
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
CVE-2021-36787 1 In2code 1 Femanager 2022-02-10 3.5 LOW 5.4 MEDIUM
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
CVE-2014-6292 1 In2code 1 Femanager 2022-02-03 6.4 MEDIUM N/A
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.
CVE-2008-2182 1 In2code 1 Powermail 2019-03-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.