Insufficient state checks lead to a vector that allows to bypass 2FA checks.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
An improper access check allows privilege escalation through the comusers batch task.
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
An improper access check allows unauthorized access to comconfig webservice endpoints.
Lack of output escaping leads to a XSS vector in the feed modules.
An improper access check allows privelege escalation through the comusers group editing webservice endpoint.
Lack of output escaping leads to a XSS vector in the readmore links for comcontent.
An improper access check allows privilege escalation through the comusers batch task.
Lack of output escaping leads to a XSS vector in the content history component.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
An improper access check allows unauthorized access to webservice endpoints.
Lack of output escaping leads to a XSS vector in the multilingual associations component.