Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

TYPO3 — Vulnerabilities & Security Advisories 118

Browse all 118 CVE security advisories affecting TYPO3. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TYPO3 is an open-source enterprise content management system primarily designed for large-scale websites and complex digital platforms. Historically, its extensive feature set and modular architecture have introduced a significant attack surface, resulting in 118 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or improper access controls within extensions. While the core framework has seen improved security practices in recent versions, legacy installations remain particularly susceptible to exploitation. Notable incidents have frequently involved unpatched third-party extensions rather than core flaws, highlighting the critical importance of rigorous extension auditing. Security advisories are regularly issued by the TYPO3 Security Team, urging administrators to maintain strict update protocols to mitigate these persistent risks associated with its broad ecosystem.

Found 20 results / 118Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-6553 TYPO3 CMS Stores Cleartext Password in User Settings Module — TYPO3 CMSCWE-312 6.5AIMediumAI2026-04-21
CVE-2026-0859 TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool — TYPO3 CMSCWE-502 7.8AIHighAI2026-01-13
CVE-2025-59022 TYPO3 CMS Allows Broken Access Control in Recycler Module — TYPO3 CMSCWE-862 8.1AIHighAI2026-01-13
CVE-2025-59021 TYPO3 CMS Allows Broken Access Control in Redirects Module — TYPO3 CMSCWE-862 4.6AIMediumAI2026-01-13
CVE-2025-59020 TYPO3 CMS Allows Broken Access Control in Edit Document Controller — TYPO3 CMSCWE-863 4.3AIMediumAI2026-01-13
CVE-2025-59019 Information Disclosure via CSV Download — TYPO3 CMSCWE-200 6.5AIMediumAI2025-09-09
CVE-2025-59018 Information Disclosure in Workspaces Module — TYPO3 CMSCWE-200 6.5AIMediumAI2025-09-09
CVE-2025-59017 Broken Access Control in Backend AJAX Routes — TYPO3 CMSCWE-862 8.8AIHighAI2025-09-09
CVE-2025-59016 Information Disclosure via File Abstraction Layer — TYPO3 CMSCWE-209 4.3AIMediumAI2025-09-09
CVE-2025-59015 Insufficient Entropy in Password Generation — TYPO3 CMSCWE-331 9.8AICriticalAI2025-09-09
CVE-2025-59014 Denial of Service in TYPO3 Bookmark Toolbar — TYPO3 CMSCWE-248 4.9AIMediumAI2025-09-09
CVE-2025-59013 Open Redirect in TYPO3 CMS — TYPO3 CMSCWE-601 6.1AIMediumAI2025-09-09
CVE-2020-15098 Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS — TYPO3 CMSCWE-325 8.8 High2020-07-29
CVE-2020-15099 Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS — TYPO3 CMSCWE-200 8.1 High2020-07-29
CVE-2020-11069 Cross-Site Request Forgery in TYPO3 CMS — TYPO3 CMSCWE-352 8.0 High2020-05-13
CVE-2020-11067 Deserialization of Untrusted Data in TYPO3 CMS — TYPO3 CMSCWE-502 8.8 High2020-05-13
CVE-2020-11066 Improperly Controlled Modification of Dynamically-Determined Object Attributes in TYPO3 CMS — TYPO3 CMSCWE-915 8.7 High2020-05-13
CVE-2020-11065 Cross-Site Scripting in TYPO3 CMS — TYPO3 CMSCWE-79 5.4 Medium2020-05-13
CVE-2020-11064 Cross-Site Scripting in TYPO3 CMS — TYPO3 CMSCWE-79 5.4 Medium2020-05-13
CVE-2020-11063 Observable Response Discrepancy in TYPO3 CMS — TYPO3 CMSCWE-204 3.7 Low2020-05-13

This page lists every published CVE security advisory associated with TYPO3. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.