Medium severityNVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-47348
CVE-2026-47348
Description
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cms-corePackagist | >= 13.0.0, < 13.4.31 | 13.4.31 |
typo3/cms-corePackagist | >= 14.0.0, < 14.3.3 | 14.3.3 |
typo3/cms-indexed-searchPackagist | >= 13.0.0, < 13.4.31 | 13.4.31 |
typo3/cms-indexed-searchPackagist | >= 14.0.0, < 14.3.3 | 14.3.3 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-cg75-qfg2-w9hjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-47348ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47348.yamlghsaWEB
- github.com/TYPO3/typo3/commit/2e96dd0e9fab7ad877b741fb9f6fc645b4270a3envdWEB
- github.com/TYPO3/typo3/commit/8004b91a5951cfe01dda8554f77d0daa82d6b899nvdWEB
- github.com/TYPO3/typo3/security/advisories/GHSA-cg75-qfg2-w9hjghsaWEB
- typo3.org/security/advisory/typo3-core-sa-2026-010nvdWEB
News mentions
1- TYPO3 CMS: Thirteen Backend Vulnerabilities Disclosed on June 9, 2026Vypr Intelligence · Jun 9, 2026