TYPO3 Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for TYPO3 products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
0
Beyond CISA KEV
3
Sensor Observed
0
Virtual Patch Available
0
TYPO3 KEVs Added by Year
3 TYPO3 KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2014-6293
SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands... |
ke_stats | High | Not in CISA | 03 Oct 2014 |
|
CVE-2012-1071
SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL... |
mv_cooking extension | High | Not in CISA | 14 Feb 2012 |
|
CVE-2011-1722
Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to... |
WEC Discussion Forum | High | Not in CISA | 19 Apr 2011 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology