TYPO3 extension
by TYPO3
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-46725 | Cri | 0.60 | — | 0.02 | May 19, 2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3… | ||
| CVE-2020-15515 | Hig | 0.57 | 8.8 | 0.02 | Jul 7, 2020 | The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution. | ||
| CVE-2026-77135 | Hig | 0.53 | — | 0.00 | Aug 25, 2026 | The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and… | ||
| CVE-2020-15513 | Med | 0.35 | 5.3 | 0.01 | Jul 7, 2020 | The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control. |
- risk 0.60cvss —epss 0.02
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3…
- risk 0.57cvss 8.8epss 0.02
The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.
- risk 0.53cvss —epss 0.00
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and…
- risk 0.35cvss 5.3epss 0.01
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.