CVE-2011-4903: TYPO3
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.
Affected products
- TYPO3 TYPO3: from 4.3.0, before 4.3.12 (fixed in 4.3.12); from 4.4.0, before 4.4.9 (fixed in 4.4.9); from 4.5.0, before 4.5.4 (fixed in 4.5.4)
Published 2019-11-06. Last modified 2026-06-16.