Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2026-6553

Published Apr 21, 2026

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This is…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0859

Published Jan 13, 2026

TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send com…

CVSS 5.2 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-59022

Published Jan 13, 2026

Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that part…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59021

Published Jan 13, 2026

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59020

Published Jan 13, 2026

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59019

Published Sep 9, 2025

Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59018

Published Sep 9, 2025

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59017

Published Sep 9, 2025

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59016

Published Sep 9, 2025

Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.1…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59015

Published Sep 9, 2025

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry ou…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59014

Published Sep 9, 2025

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑s…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59013

Published Sep 9, 2025

An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7900

Published Jul 22, 2025

The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below,…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47941

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor auth…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-47940

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, admini…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-47939

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of an…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-47938

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-47937

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-47936

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, Webhooks are inheren…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-55945

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55924

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55923

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55922

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55921

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55920

Published Jan 14, 2025

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 518 CVEsPage 1 of 21