typo3

346 tracked vulnerabilities.

CVE-2025-59013 MEDIUM
TYPO3 CMS Open Redirect via GeneralUtility::sanitizeLocalUrl
Sep 09, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-9573 HIGH
TYPO3 ns_backup <13.0.2 - Command Injection
Sep 02, 2025
EPSS 0.00
CVE-2025-7900 MEDIUM
TYPO3 femanager <6.4.1, 7.0.0-7.5.2, 8.0.0-8.3.0 - Info Disclosure
Jul 22, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7899 MEDIUM
Powermail <13.0.0 - Info Disclosure
Jul 22, 2025
EPSS 0.00
CVE-2025-48207 HIGH
TYPO3 reint_downloadmanager <5.0.0 - Info Disclosure
May 21, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-48205 HIGH
TYPO3 sr_feuser_register <12.4.8 - Info Disclosure
May 21, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-48204 MEDIUM
ns_backup < 13.0.1 - OS Command Injection
May 21, 2025
CVSS 6.8
EPSS 0.01
CVE-2025-48203 MEDIUM
cs_seo 6.3.0-6.7.9, 7.0.0-7.4.9, 8.0.0-8.3.9, 9.0.0-9.2.0 - Cross-Site Scripting
May 21, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-48202 MEDIUM
TYPO3 femanager <8.2.1 - Info Disclosure
May 21, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-48201 HIGH
TYPO3 ns_backup <13.0.0 - Info Disclosure
May 21, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-48200 CRITICAL
sr_feuser_register 5.1.0-12.4.8 - Remote Code Execution via Untrusted Data Deserialization
May 21, 2025
CVSS 10.0
EPSS 0.02
CVE-2025-47941 HIGH
TYPO3 <12.4.31 LTS & <13.4.2 LTS - Auth Bypass
May 20, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-47940 HIGH
TYPO3 <10.4.50 ELTS, <11.5.44 ELTS, <12.4.31 LTS, <13.4.12 LTS - Pr...
May 20, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-47939 MEDIUM
TYPO3 9.0.0-9.5.50 - Unrestricted Upload of File with Dangerous Type in File Management Module
May 20, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-47938 LOW
TYPO3 <9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, 13.4.1...
May 20, 2025
CVSS 3.8
EPSS 0.00
CVE-2025-47937 LOW
TYPO3 9.0.0-9.5.50 - Incorrect Authorization in Database Abstraction Layer
May 20, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-47936 LOW
TYPO3 12.0.0-12.4.30 and 13.0.0-13.4.1 - Authenticated Server-Side Request Forgery via Webhooks
May 20, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-24856 MEDIUM
TYPO3 oidc <4.0.0 - Privilege Escalation
Mar 16, 2025
CVSS 4.2
EPSS 0.00
CVE-2024-55945 MEDIUM
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-55924 HIGH
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 8.0
EPSS 0.01
CVE-2024-55923 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-55922 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-55921 HIGH
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery and Remote Code Execution via Extension Manager Module
Jan 14, 2025
CVSS 7.5
EPSS 0.03
CVE-2024-55920 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-55894 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
Jan 14, 2025
CVSS 4.3
EPSS 0.00