typo3

346 tracked vulnerabilities.

CVE-2026-8827 HIGH
SQL Injection in extension "Address List" (tt_address)
May 19, 2026
EPSS 0.00
CVE-2026-8727 HIGH
Remote Code Execution in extension "Site Crawler" (crawler)
May 19, 2026
EPSS 0.00
CVE-2026-8726 HIGH
SQL Injection in extension "News system" (news)
May 19, 2026
EPSS 0.00
CVE-2026-46725 CRITICAL
Remote Code Execution in extension "Content Element Selector" (ceselector)
May 19, 2026
EPSS 0.00
CVE-2026-46724 MEDIUM
Path Traversal in extension "Faceted Search" (ke_search)
May 19, 2026
EPSS 0.00
CVE-2026-46723 MEDIUM
Information Disclosure in extension "Faceted Search" (ke_search)
May 19, 2026
EPSS 0.00
CVE-2026-46722 MEDIUM
XML External Entity Injection in extension "Faceted Search" (ke_search)
May 19, 2026
EPSS 0.00
CVE-2026-46721 MEDIUM
Broken Access Control in extension "Frontend User Registration" (sf_register)
May 19, 2026
EPSS 0.00
CVE-2026-6553 HIGH
TYPO3 CMS Stores Cleartext Password in User Settings Module
Apr 21, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-4208 HIGH
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
Mar 17, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-4202 MEDIUM
Broken Access Control in extension "Redirect Tab"
Mar 17, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-1323 HIGH
Insecure Deserialization in extension "Mailqueue" (mailqueue)
Mar 17, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-0895 MEDIUM
TYPO3 Extension Mailqueue < 0.4.3 and 0.5.0 < 0.5.1 - Insecure Deserialization
Jan 20, 2026
EPSS 0.00
CVE-2026-0859 HIGH
Typo3 < 10.4.55 - Insecure Deserialization
Jan 13, 2026
CVSS 7.8
EPSS 0.00
CVE-2025-59022 HIGH
Typo3 < 10.4.55 - Missing Authorization
Jan 13, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-59021 MEDIUM
Typo3 < 10.4.55 - Missing Authorization
Jan 13, 2026
CVSS 6.4
EPSS 0.00
CVE-2025-59020 MEDIUM
Typo3 < 10.4.55 - Incorrect Authorization
Jan 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-12998 HIGH
TYPO3 Extension Modules <4.3.11-5.7.4-6.4.2-7.5.5 - Auth Bypass
Nov 12, 2025
EPSS 0.00
CVE-2025-10316 LOW
TYPO3 Form to Database < 2.2.5, 3.0.0-3.2.1, 4.0.0-4.2.2, 5.0.0-5.0.1 - Cross-Site Scripting
Sep 16, 2025
EPSS 0.00
CVE-2025-59019 MEDIUM
TYPO3 CMS 11.0.0-11.5.47 12.0.0-12.4.36 13.0.0-13.4.17 - Unauthorized Information Disclosure via CSV Download Feature
Sep 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-59018 MEDIUM
TYPO3 CMS 9.0.0-13.4.17 - Unauthorized Sensitive Information Exposure via Workspace Module
Sep 09, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-59017 HIGH
TYPO3 CMS 9.0.0-13.4.17 - Missing Authorization in Backend Routing
Sep 09, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-59016 MEDIUM
TYPO3 CMS 9.0.0-13.4.17 - Authenticated Sensitive Information Disclosure
Sep 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-59015 MEDIUM
TYPO3 CMS <13.4.17 - Info Disclosure
Sep 09, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-59014 LOW
TYPO3 CMS 11.0.0-11.5.47 12.0.0-12.4.36 13.0.0-13.4.17 - Authenticated Denial of Service via Bookmark Toolbar
Sep 09, 2025
CVSS 2.7
EPSS 0.00