Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TYPO3 — Vulnerabilities & Security Advisories 143

Browse all 143 CVE security advisories affecting TYPO3. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TYPO3 is an open-source enterprise content management system primarily designed for large-scale websites and complex digital platforms. Historically, its extensive feature set and modular architecture have introduced a significant attack surface, resulting in 118 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation or improper access controls within extensions. While the core framework has seen improved security practices in recent versions, legacy installations remain particularly susceptible to exploitation. Notable incidents have frequently involved unpatched third-party extensions rather than core flaws, highlighting the critical importance of rigorous extension auditing. Security advisories are regularly issued by the TYPO3 Security Team, urging administrators to maintain strict update protocols to mitigate these persistent risks associated with its broad ecosystem.

HighTYPO3-CORE-SA-2026-0212026-08-11
[SECURITY] Prevent local Fetch/XHR-based request forgery via XSS · TYPO3/typo3@4a75e86 · GitHub
High2026-07-15
[SECURITY] Register MimeTypeValidator for file uploads at runtime · TYPO3/typo3@817ad41 · GitHub
HighCVE-2020-123052026-07-15
[SECURITY] Register MimeTypeValidator for file uploads at runtime · TYPO3/typo3@cfda210 · GitHub
High2026-06-13
[SECURITY] Mitigate raw-text bypass with ALLOW_INSECURE_RAW_TEXT · TYPO3/html-sanitizer@bd1a88d · GitHub
HighCVE-2026-115072026-06-13
[SECURITY] Properly evaluate .form.yaml file extension · TYPO3/typo3@040d50d · GitHub
MediumCVE-2024-473522026-06-13
[SECURITY] Check file permissions before showing meta data · TYPO3/typo3@17a3b78 · GitHub
HighCVE-2026-427382026-06-13
[SECURITY] Fix path prefix confusion in isAllowedAbsPath · TYPO3/typo3@150a983 · GitHub
HighCVE-2026-0122026-06-13
[SECURITY] Prevent unauthorized record move via DataHandler · TYPO3/typo3@1953569 · GitHub
MediumCVE-2024-473462026-06-13
[SECURITY] Properly detect .form.yaml suffixes in resource layer · TYPO3/typo3@2030617 · GitHub
High2026-06-13
[SECURITY] Fix open redirection in GeneralUtility::sanitizeLocalUrl · TYPO3/typo3@22c2dd5 · GitHub
HighCVE-2026-473512026-06-13
[SECURITY] Check record/file access when adding records to clipboard · TYPO3/typo3@2740707 · GitHub
UnknownCVE-2024-473472026-06-13
[SECURITY] Fix open redirection in GeneralUtility::sanitizeLocalUrl · TYPO3/typo3@3ffc083 · GitHub
HighCVE-2024-473482026-06-13
[SECURITY] Encode indexed search results in frontend rendering · TYPO3/typo3@2e96dd0 · GitHub
HighCVE-2024-107382026-06-13
[SECURITY] Fix path prefix confusion in isAllowedAbsPath · TYPO3/typo3@44c2fa9 · GitHub
Unknown2026-06-13
[SECURITY] Properly evaluate .form.yaml file extension · TYPO3/typo3@50974c6 · GitHub
High2026-06-13
[SECURITY] Deny destructive write actions on mount folders · TYPO3/typo3@504e724 · GitHub
HighCVE-2025-473382026-06-13
[SECURITY] Encode indexed search results in frontend rendering · TYPO3/typo3@8004b91 · GitHub
Medium2026-06-13
[SECURITY] Validate permissions on record undelete · TYPO3/typo3@92f08d8 · GitHub
HighCVE-2024-472822026-06-13
[SECURITY] Validate permissions on record undelete · TYPO3/typo3@9f17a30 · GitHub
High2026-06-13
[SECURITY] Avoid download from fallback storage in FileDownloadContro… · TYPO3/typo3@ad636b6 · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with TYPO3. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.