typo3 -- multiple vulnerabilities

Affected packages
typo3-11-php80 < 11.5.30
typo3-11-php81 < 11.5.30
typo3-12-php80 < 12.4.4
typo3-12-php81 < 12.4.4


VuXML ID b1ac663f-3aa9-11ee-b887-b42e991fc52e
Discovery 2023-07-25
Entry 2023-08-14

TYPO3 reports:

TYPO3-CORE-SA-2023-002: By-passing Cross-Site Scripting Protection in HTML Sanitizer

TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution

TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin


CVE Name CVE-2023-37905
CVE Name CVE-2023-38499
CVE Name CVE-2023-38500