Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TYPO3 CMS — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in TYPO3 CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness and vulnerability data for the TYPO3 CMS platform, a widely used open-source content management system. It collects detailed records of security flaws, configuration errors, and logic bugs identified in TYPO3 installations and related components over a comprehensive historical time range. By centralizing this information, the page allows security professionals and administrators to track vendor advisories from the TYPO3 project, understand the specific characteristics and impact of different weakness classes affecting this software stack, and look up a product's vulnerability history to assess past risks and current exposure levels. The data is organized to facilitate efficient risk assessment and patch management, enabling users to correlate specific vulnerability types with their corresponding remediation steps. This resource serves as a centralized reference for understanding the security landscape of TYPO3, helping stakeholders identify patterns in reported issues and prioritize mitigation efforts based on severity and prevalence. All entries are curated to provide accurate context regarding the affected versions and the nature of the security implications, ensuring that teams can make informed decisions about system hardening and update schedules. The aggregation focuses on clarity and actionability, stripping away unnecessary noise to highlight the essential technical details needed for effective security operations.

Vendor: TYPO3

CVE IDTitleCVSSSeverityPublished
CVE-2026-15305 TYPO3 CMS - Unrestricted File Upload in Form Framework CWE-351--2026-07-14
CVE-2026-49742 TYPO3 CMS - Broken Access Control in Media Module CWE-22--2026-06-09
CVE-2026-49741 TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework CWE-862--2026-06-09
CVE-2026-49740 TYPO3 CMS - Insecure Deserialization in Core API CWE-502--2026-06-09
CVE-2026-49738 TYPO3 CMS - Broken Access Control in File Abstraction Layer CWE-22--2026-06-09
CVE-2026-47352 TYPO3 CMS - Broken Access Control in Backend API CWE-862--2026-06-09
CVE-2026-47351 TYPO3 CMS - Broken Access Control in Clipboard CWE-862--2026-06-09
CVE-2026-47350 TYPO3 CMS - Broken Access Control in DataHandler CWE-862--2026-06-09
CVE-2026-47349 TYPO3 CMS - Broken Access Control in Recycler CWE-862--2026-06-09
CVE-2026-47348 TYPO3 CMS - Cross-Site Scripting in Indexed Search CWE-79--2026-06-09
CVE-2026-47347 TYPO3 CMS - Open Redirect in Core Utilities CWE-601--2026-06-09
CVE-2026-47346 TYPO3 CMS - Broken Access Control in Form Framework CWE-178--2026-06-09
CVE-2026-47343 TYPO3 CMS - Destructive Actions on File Mount Folders CWE-862--2026-06-09
CVE-2026-11607 TYPO3 CMS - Broken Access Control in Form Framework CWE-862--2026-06-09
CVE-2026-6553 TYPO3 CMS Stores Cleartext Password in User Settings Module CWE-312 6.5AIMediumAI2026-04-21
CVE-2026-0859 TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool CWE-502 7.8AIHighAI2026-01-13
CVE-2025-59022 TYPO3 CMS Allows Broken Access Control in Recycler Module CWE-862 8.1AIHighAI2026-01-13
CVE-2025-59021 TYPO3 CMS Allows Broken Access Control in Redirects Module CWE-862 4.6AIMediumAI2026-01-13
CVE-2025-59020 TYPO3 CMS Allows Broken Access Control in Edit Document Controller CWE-863 4.3AIMediumAI2026-01-13
CVE-2025-59019 Information Disclosure via CSV Download CWE-200 6.5AIMediumAI2025-09-09
CVE-2025-59018 Information Disclosure in Workspaces Module CWE-200 6.5AIMediumAI2025-09-09
CVE-2025-59017 Broken Access Control in Backend AJAX Routes CWE-862 8.8AIHighAI2025-09-09
CVE-2025-59016 Information Disclosure via File Abstraction Layer CWE-209 4.3AIMediumAI2025-09-09
CVE-2025-59015 Insufficient Entropy in Password Generation CWE-331 9.8AICriticalAI2025-09-09
CVE-2025-59014 Denial of Service in TYPO3 Bookmark Toolbar CWE-248 4.9AIMediumAI2025-09-09
CVE-2025-59013 Open Redirect in TYPO3 CMS CWE-601 6.1AIMediumAI2025-09-09
CVE-2020-15098 Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS CWE-325 8.8 High2020-07-29
CVE-2020-15099 Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS CWE-200 8.1 High2020-07-29
CVE-2020-11069 Cross-Site Request Forgery in TYPO3 CMS CWE-352 8.0 High2020-05-13
CVE-2020-11067 Deserialization of Untrusted Data in TYPO3 CMS CWE-502 8.8 High2020-05-13

All 34 known CVE vulnerabilities affecting TYPO3 CMS with full Chinese analysis, references, and POCs where available.