FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-06-07 10:36:35 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
0eab001a-9708-11ec-96c9-589cfc0f81b0typo3 -- XSS vulnerability in svg-sanitize

The TYPO3 project reports:

The SVG sanitizer library enshrined/svg-sanitize before version 0.15.0 did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as text/html) was susceptible to cross-site scripting. Plain SVG files (fetched as image/svg+xml) were not affected.


Discovery 2022-02-22
Entry 2022-02-27
typo3-10-php74
< 10.4.25

typo3-11-php74
typo3-11-php80
typo3-11-php81
< 11.5.7

CVE-2022-23638
https://github.com/typo3/typo3/commit/9940defb21
https://typo3.org/article/typo3-psa-2022-001
b1ac663f-3aa9-11ee-b887-b42e991fc52etypo3 -- multiple vulnerabilities

TYPO3 reports:

TYPO3-CORE-SA-2023-002: By-passing Cross-Site Scripting Protection in HTML Sanitizer

TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution

TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin


Discovery 2023-07-25
Entry 2023-08-14
typo3-11-php80
typo3-11-php81
< 11.5.30

typo3-12-php80
typo3-12-php81
< 12.4.4

CVE-2023-38500
CVE-2023-38499
CVE-2023-37905
https://typo3.org/article/typo3-1244-and-11530-security-releases-published