VYPR
High severity8.1NVD Advisory· Published Jan 23, 2017· Updated May 13, 2026

CVE-2016-5091

CVE-2016-5091

Description

Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cms-extbasePackagist
< 6.2.246.2.24
typo3/cms-extbasePackagist
>= 7.0, < 7.6.87.6.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.