clickstorm/cs-seo
[clickstorm] SEO
Activity
- Latest release
- 1d ago
- Total releases
- 90
- Cadence
- ~20 days
- Last 12 months
- 12
Reach
- Stars
- 37
Details
- License
- unknown
- First release
- Aug 08, 2016
| Version | Released | |
|---|---|---|
10.2.1
patch
| ||
8.5.2
patch
| ||
9.6.1
patch
| ||
8.5.1
patch
| ||
10.2.0
minor
| ||
9.6.0
minor
| ||
10.1.0
minor
| ||
10.0.0
major
| ||
9.5.0
minor
| ||
8.5.0
minor
| ||
8.4.2
patch
| ||
9.4.0
minor
| ||
9.3.1
patch
| ||
8.4.1
patch
| ||
6.8.0
minor
| ||
7.5.0
minor
| ||
8.4.0
minor
| ||
9.3.0
minor
| ||
9.2.0
minor
1 CVE
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev | ||
8.3.0
minor
1 CVE
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev | ||
7.4.0
minor
1 CVE
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev | ||
6.7.0
minor
1 CVE
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev | ||
9.1.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
9.0.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
9.0.0
major
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.2.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.2.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.1.2
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.1.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.1.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.0.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.3.3
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
8.0.0
major
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.3.2
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.3.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.3.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.6.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.2.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.5.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.2.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.1.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.0.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.4.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
7.0.0
major
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.4.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.3.2
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.3.1
patch
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.3.0
minor
2 CVEs
CVE-2025-48203
GHSA-6p8w-pc35-mqv8
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
5.5
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
Low
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (cs_seo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output. Affected versions
9.0.0
9.0.1
9.1.0
9.2.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
+ 18 more Show less
7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
6.7.0
Fixed in
6.8.0
7.5.0
8.4.0
9.3.0
References
Updated May 21, 2025 · Source: OSV.dev
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.2.1
patch
1 CVE
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev | ||
6.2.0
minor
1 CVE
CVE-2025-30081
GHSA-vmgw-24w6-9v82
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
A cross-site scripting (XSS) vulnerability has been discovered in the Clickstorm SEO extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 6.7.0, 7.4.0, 8.3.0 and 9.2.0 are available for download. Affected versions
9.0.0
9.0.1
9.1.0
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
7.0.0
7.0.1
+ 19 more Show less
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.3.3
6.0.0
6.1.0
6.1.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.5.0
6.6.0
Fixed in
6.7.0
7.4.0
8.3.0
9.2.0
References Updated Mar 19, 2025 · Source: OSV.dev |