296,747
Total vulnerabilities in the database
TYPO3 Fluid Engine (package typo3fluid/fluid) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like {showFullName ? fullName : defaultValue}. Updated versions of this package are bundled in following TYPO3 (typo3/cms-core) versions as well: TYPO3 v8.7.25 (using typo3fluid/fluid v2.5.4) and TYPO3 v9.5.6 (using typo3fluid/fluid v2.6.1).
| Software | From | Fixed in |
|---|---|---|
| typo3 / fluid_engine | 2.6.0 | 2.6.1 |
| typo3 / fluid_engine | 2.5.0 | 2.5.5 |
| typo3 / fluid_engine | 2.4.0 | 2.4.1 |
| typo3 / fluid_engine | 2.3.0 | 2.3.5 |
| typo3 / fluid_engine | 2.2.0 | 2.2.1 |
| typo3 / fluid_engine | 2.1.0 | 2.1.4 |
| typo3 / fluid_engine | - | 2.0.5 |
| typo3 / typo3 | 9.5.6 | 9.5.6.x |
| typo3 / typo3 | 8.7.25 | 8.7.25.x |
typo3fluid / fluid
|
2.0.0 | 2.0.5 |
typo3fluid / fluid
|
2.1.0 | 2.1.4 |
typo3fluid / fluid
|
2.2.0 | 2.2.1 |
typo3fluid / fluid
|
2.3.0 | 2.3.5 |
typo3fluid / fluid
|
2.4.0 | 2.4.1 |
typo3fluid / fluid
|
2.5.0 | 2.5.5 |
typo3fluid / fluid
|
2.6.0 | 2.6.1 |