VendorsDated News Projectdated_newsall versions
Vulnerabilities

Dated News Project Dated News

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-36789
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
Published 2021-08-13 · Modified
9.8EPSS 0.010
CVE-2021-36792
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.
Published 2021-08-13 · Modified
7.2EPSS 0.007
CVE-2021-36790
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
Published 2021-08-13 · Modified
6.1EPSS 0.006
CVE-2021-36791
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
Published 2021-08-13 · Modified
5.3EPSS 0.008