in2code records
10 published records for vendor in2code.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 90%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2022-35628No exploit | A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.in2code · living user experience · CWE-89 | Critical9.8 | — | 26.8% | Jul 12, 2022 |
39Monitor | CVE-2024-45233No exploit | An issue was discovered in powermail extension through 12.3.5 for TYPO3.in2code · powermail · CWE-284 | Critical9.8 | — | 0.4% | Aug 28, 2024 |
30Monitor | CVE-2023-25013No exploit | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3.in2code · femanager · CWE-306 | High7.5 | — | 0.5% | Feb 1, 2023 |
30Monitor | CVE-2023-25014No exploit | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3.in2code · femanager · CWE-306 | High7.5 | — | 0.5% | Feb 1, 2023 |
30Monitor | CVE-2024-47047No exploit | An issue was discovered in the powermail extension through 12.4.0 for TYPO3.in2code · powermail · CWE-639 | High7.5 | — | 0.5% | Sep 17, 2024 |
25Monitor | CVE-2014-6292No exploit | The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspin2code · femanager | Medium6.4 | — | 1.3% | Oct 3, 2014 |
21Monitor | CVE-2021-36787No exploit | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.in2code · femanager · CWE-79 | Medium5.4 | — | 1.3% | Aug 13, 2021 |
21Monitor | CVE-2022-44543No exploit | The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groupin2code · femanager | Medium5.3 | — | 0.6% | Dec 12, 2023 |
21Monitor | CVE-2024-45232No exploit | An issue was discovered in powermail extension through 12.3.5 for TYPO3.in2code · powermail · CWE-639 | Medium5.3 | — | 0.3% | Aug 28, 2024 |
17Monitor | CVE-2008-2182No exploit | Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web in2code · powermail · CWE-79 | Medium4.3 | — | 1.3% | May 13, 2008 |
- CVE-2022-3562847Plan
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
CriticalCVSS 9.8No exploitEPSS 27%in2code · living user experienceJul 12, 2022
- CVE-2024-4523339Monitor
An issue was discovered in powermail extension through 12.3.5 for TYPO3.
CriticalCVSS 9.8No exploitEPSS 0%in2code · powermailAug 28, 2024
- CVE-2023-2501330Monitor
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3.
HighCVSS 7.5No exploitEPSS 1%in2code · femanagerFeb 1, 2023
- CVE-2023-2501430Monitor
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3.
HighCVSS 7.5No exploitEPSS 1%in2code · femanagerFeb 1, 2023
- CVE-2024-4704730Monitor
An issue was discovered in the powermail extension through 12.4.0 for TYPO3.
HighCVSS 7.5No exploitEPSS 0%in2code · powermailSep 17, 2024
- CVE-2014-629225Monitor
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unsp
MediumCVSS 6.4No exploitEPSS 1%in2code · femanagerOct 3, 2014
- CVE-2021-3678721Monitor
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
MediumCVSS 5.4No exploitEPSS 1%in2code · femanagerAug 13, 2021
- CVE-2022-4454321Monitor
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted group
MediumCVSS 5.3No exploitEPSS 1%in2code · femanagerDec 12, 2023
- CVE-2024-4523221Monitor
An issue was discovered in powermail extension through 12.3.5 for TYPO3.
MediumCVSS 5.3No exploitEPSS 0%in2code · powermailAug 28, 2024
- CVE-2008-218217Monitor
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web
MediumCVSS 4.3No exploitEPSS 1%in2code · powermailMay 13, 2008