Dkd's vulnerability profile centers on its Direct Mail product, a narrowly scoped offering where the recurring exposure reflects application-level authorization and information-handling issues such as missing authorization controls, open redirects, and unthrottled resource allocation. The weakness classes observed—particularly authorization gaps and sensitive-data exposure—are characteristic of web-facing communication platforms where access control and input validation demand close attention. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dkd over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7400HIGH The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes. | Dec 29, 2017 | 7.5 | 25 | NO | NO |
CVE-2020-12699MEDIUM The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. | May 13, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-12700MEDIUM The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query. | May 13, 2020 | 4.3 | 17 | NO | NO |
CVE-2020-12697MEDIUM The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries. | May 13, 2020 | 5.3 | 16 | NO | NO |
CVE-2019-16698MEDIUM The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users t | Oct 16, 2019 | 4.3 | 16 | NO | NO |
CVE-2020-12698MEDIUM The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables. | May 13, 2020 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dkd.
Media articles that mention a CVE ID that affects a product developed by Dkd — matched by CVE ID, not by vendor name.