Home

Description

The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before 3.2.2, from 4.0.0 before 4.2.3, from 5.0.0 before 5.0.2.

PUBLISHED Reserved 2025-09-12 | Published 2025-09-16 | Updated 2025-09-16 | Assigner TYPO3




LOW: 2.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

Any version before 2.2.5
affected

3.0.0 (semver) before 3.2.2
affected

4.0.0 (semver) before 4.2.3
affected

5.0.0 (semver) before 5.0.2
affected

Credits

Sascha Egerer reporter

References

typo3.org/security/advisory/typo3-ext-sa-2025-012

cve.org (CVE-2025-10316)

nvd.nist.gov (CVE-2025-10316)

Download JSON