Lack of escaping leads to an XSS vulnerability in the update list view of cominstaller.
An improper access check allows privileged users to overwrite media files without editing permissions.
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Lack of escaping leads to an XSS vulnerability in the file management view of comtemplates.
An improper access check allows unauthorized users to access workflow stage and transition information.
An improper access check allows users to display a list of modules in the frontend.
An improper access check allows unauthorized users to access comprivacy datasets.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
An improper access check allows user to download vcard exports of comcontact contacts that are inaccessible.
Lack of validation leads to an XSS vulnerability in the MFA management views.
Improper validation leads to a generic XSS vector in the language override feature.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for comfinder.
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of comusers.
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
Lack of input filtering leads to an XSS vector in the HTML filter code.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
An improper access check allows privilege escalation through the comusers batch task.
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
Lack of output escaping leads to a XSS vector in the feed modules.
Lack of output escaping leads to a XSS vector in the readmore links for comcontent.
Lack of output escaping leads to a XSS vector in the content history component.
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping for article titles leads to XSS vectors in various locations.
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.