CVE-2012-1608: TYPO3
Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
Affected products
- TYPO3 TYPO3: version 4.4.0 only; version 4.4.1 only; version 4.4.2 only; version 4.4.3 only; version 4.4.4 only; version 4.4.5 only; …
Published 2012-09-04. Last modified 2026-06-16.