CVE-2014-6290: News Project News

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.

Affected products

  • News Project News: up to and including 3.5.1; version 3.0.0 only; version 3.0.1 only; version 3.1.0 only; version 3.2.0 only; version 3.2.1 only; …

Published 2014-10-03. Last modified 2026-06-17.