In2code
In2code Femanager: vulnerabilidades y CVE
In2code Femanager tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-45023 | Media (4.2) | 0.14% | — | 14 sept 2026 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. |
| CVE-2025-48202 | Media (5.3) | 0.28% | — | 21 may 2025 | The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2022-44543 | Media (5.3) | 0.60% | — | 12 dic 2023 | The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because… |
| CVE-2023-25014 | Alta (7.5) | 0.50% | — | 2 feb 2023 | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend… |
| CVE-2023-25013 | Alta (7.5) | 0.50% | — | 2 feb 2023 | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of… |
| CVE-2021-36787 | Media (5.4) | 1.3% | — | 13 ago 2021 | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. |
| CVE-2014-6292 | Media (6.4) | 1.3% | — | 3 oct 2014 | The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors. |