Joachim Ruhs maintains a small portfolio of web-based applications spanning locator, educator, event-management, and file-management tools, where the recurrent exposure centers on application-layer input-handling weaknesses such as SQL injection and cross-site scripting. These vulnerability classes reflect common risks in web-application development where user input validation and output encoding are critical; defenders should apply standard secure-coding practices and web-application firewall protections to instances of these products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joachim Ruhs over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5303HIGH Unspecified vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 has unknown impact and remote attack vectors, related to "Insecure Unserialize." | Aug 16, 2013 | 10.0 | 25 | NO | NO |
CVE-2013-5304HIGH SQL injection vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Aug 16, 2013 | 7.5 | 22 | NO | NO |
CVE-2009-4949HIGH SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Jul 22, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-4952HIGH SQL injection vulnerability in the FE user statistic (festat) extension before 0.2.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Oct 9, 2011 | 7.5 | 21 | NO | NO |
CVE-2010-4950HIGH SQL injection vulnerability in the Event (event) extension before 0.3.7 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Oct 9, 2011 | 7.5 | 21 | NO | NO |
CVE-2010-1009HIGH SQL injection vulnerability in the Educator extension 0.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Mar 19, 2010 | 7.5 | 20 | NO | NO |
CVE-2009-4802HIGH SQL injection vulnerability in the Flat Manager (flatmgr) extension before 1.9.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Apr 23, 2010 | 7.5 | 19 | NO | NO |
CVE-2009-4948MEDIUM Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vector | Jul 22, 2010 | 4.3 | 16 | NO | NO |
CVE-2013-5305MEDIUM Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecif | Aug 16, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joachim Ruhs.
Media articles that mention a CVE ID that affects a product developed by Joachim Ruhs — matched by CVE ID, not by vendor name.