CVE-2025-59016
MEDIUMTypo3 < 9.5.55 - Error Information Exposure
Title source: ruleDescription
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.
Scores
CVSS v3
4.3
EPSS
0.0004
EPSS Percentile
12.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-209
Status
published
Affected Products (2)
typo3/typo3
< 9.5.55
typo3/cms-core
< 12.4.37Packagist
Timeline
Published
Sep 09, 2025
Tracked Since
Feb 18, 2026