The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
An improper access check allows unauthorized access to webservice endpoints.
An improper access check allows unauthorized access to comconfig webservice endpoints.
An improper access check allows privilege escalation through the comusers batch task.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
An improper access check allows privelege escalation through the comusers group editing webservice endpoint.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
Lack of output escaping leads to a XSS vector in the feed modules.
Lack of output escaping leads to a XSS vector in the content history component.
Lack of output escaping leads to a XSS vector in the readmore links for comcontent.
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
An improper access check allows privilege escalation through the comusers batch task.