TYPO3
TYPO3 is a web content management system (CMS) written in the programming language PHP. It is free and open-source software released under the GNU General Public License version 2.
Products
373- 253 CVEs
- 8 CVEs
- 6 CVEs
- 6 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- View all 373 products →
Recent CVEs
614| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29601 | Cri | 0.64 | 9.8 | 0.01 | Jul 12, 2022 | The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection. | ||
| CVE-2022-29600 | Cri | 0.64 | 9.8 | 0.01 | Jul 12, 2022 | The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection. | ||
| CVE-2021-36789 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | ||
| CVE-2011-3584 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2019 | The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input. | ||
| CVE-2011-3583 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2019 | It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two… | ||
| CVE-2011-4628 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request. | ||
| CVE-2019-11830 | Cri | 0.64 | 9.8 | 0.03 | May 9, 2019 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism. | ||
| CVE-2015-1401 | Cri | 0.64 | 9.8 | 0.03 | Aug 28, 2017 | Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3. | ||
| CVE-2026-77138 | Cri | 0.61 | — | 0.01 | Aug 25, 2026 | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the… | ||
| CVE-2026-46725 | Cri | 0.60 | — | 0.02 | May 19, 2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3… | ||
| CVE-2022-47409 | Cri | 0.59 | 9.1 | 0.01 | Dec 14, 2022 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction… | ||
| CVE-2026-77143 | Hig | 0.57 | — | 0.00 | Aug 25, 2026 | The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and… | ||
| CVE-2026-77142 | Hig | 0.57 | — | 0.00 | Aug 25, 2026 | The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor… | ||
| CVE-2026-77141 | Hig | 0.57 | — | 0.00 | Aug 25, 2026 | The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to… | ||
| CVE-2026-77140 | Hig | 0.57 | — | 0.00 | Aug 25, 2026 | The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update… | ||
| CVE-2024-45233 | Cri | 0.57 | 9.8 | 0.00 | Aug 29, 2024 | An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the… | ||
| CVE-2021-43563 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This… | ||
| CVE-2021-43562 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote… | ||
| CVE-2020-15086 | Cri | 0.57 | 9.8 | 0.03 | Jul 29, 2020 | In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message… | ||
| CVE-2020-15515 | Hig | 0.57 | 8.8 | 0.02 | Jul 7, 2020 | The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution. |
- risk 0.64cvss 9.8epss 0.01
The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
- risk 0.64cvss 9.8epss 0.01
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two…
- risk 0.64cvss 9.8epss 0.02
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.
- risk 0.64cvss 9.8epss 0.03
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
- risk 0.64cvss 9.8epss 0.03
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
- risk 0.61cvss —epss 0.01
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the…
- risk 0.60cvss —epss 0.02
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3…
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction…
- risk 0.57cvss —epss 0.00
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and…
- risk 0.57cvss —epss 0.00
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor…
- risk 0.57cvss —epss 0.00
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to…
- risk 0.57cvss —epss 0.00
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update…
- risk 0.57cvss 9.8epss 0.00
An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote…
- risk 0.57cvss 9.8epss 0.03
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message…
- risk 0.57cvss 8.8epss 0.02
The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.