CVE-2025-59016

MEDIUM

Typo3 < 9.5.55 - Error Information Exposure

Title source: rule

Description

Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-209
Status published

Affected Products (2)

typo3/typo3 < 9.5.55
typo3/cms-core < 12.4.37Packagist

Timeline

Published Sep 09, 2025
Tracked Since Feb 18, 2026