VYPR

TYPO3 CMS

by TYPO3

Source repositories

CVEs (3)

  • CVE-2026-19418HigAug 11, 2026
    risk 0.40cvss epss 0.00

    The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a…

  • CVE-2026-15305MedJul 14, 2026
    risk 0.34cvss epss 0.00

    Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form…

  • CVE-2026-77132MedSep 8, 2026
    risk 0.27cvss epss 0.00

    It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted…