VYPR

Vendor CVEs

TYPO3

All CVEs

614 total · sorted by risk
  • CVE-2026-15305MedJul 14, 2026
    risk 0.34cvss —epss 0.00

    Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form…

  • CVE-2026-49740MedJun 9, 2026
    risk 0.34cvss —epss 0.00

    TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could…

  • CVE-2025-59013MedSep 9, 2025
    risk 0.33cvss 6.1epss 0.00

    An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a…

  • CVE-2023-26091MedFeb 26, 2023
    risk 0.33cvss 6.1epss 0.00

    The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails.

  • CVE-2022-36020MedSep 13, 2022
    risk 0.33cvss 6.1epss 0.01

    The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special…

  • CVE-2020-16095MedJul 29, 2020
    risk 0.33cvss 6.1epss 0.01

    The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.

  • CVE-2020-8091MedJan 27, 2020
    risk 0.33cvss 6.1epss 0.05

    svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.

  • CVE-2010-3672MedNov 5, 2019
    risk 0.33cvss 6.1epss 0.01

    TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.

  • CVE-2015-8760MedJan 8, 2016
    risk 0.33cvss 6.1epss 0.02

    The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."

  • CVE-2024-34537MedOct 28, 2024
    risk 0.32cvss 4.9epss 0.01

    TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS,…

  • CVE-2022-31050MedJun 14, 2022
    risk 0.32cvss 6.0epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the corresponding user account was degraded to lower permissions or…

  • CVE-2022-23501MedDec 14, 2022
    risk 0.31cvss 5.9epss 0.00

    TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions),…

  • CVE-2022-23500MedDec 14, 2022
    risk 0.31cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to be shown as an error message…

  • CVE-2022-36104MedSep 13, 2022
    risk 0.31cvss 5.9epss 0.02

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as an error message from another…

  • CVE-2021-21338MedMar 23, 2021
    risk 0.31cvss 4.7epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and…

  • CVE-2022-23504MedDec 14, 2022
    risk 0.30cvss 5.7epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend…

  • CVE-2025-47939MedMay 20, 2025
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context.…

  • CVE-2024-55945MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-55922MedJan 14, 2025
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-34357MedMay 14, 2024
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID…

  • CVE-2024-34356MedMay 14, 2024
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a…

  • CVE-2022-23502MedDec 14, 2022
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This…

  • CVE-2022-36106MedSep 13, 2022
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password reset link could be used to perform a…

  • CVE-2022-36105MedSep 13, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing and non-existing user accounts. Extension…

  • CVE-2022-31049MedJun 14, 2022
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, user submitted content was used without being properly encoded in HTML emails sent to users. The actually affected components were mail clients used to view those…

  • CVE-2022-31048MedJun 14, 2022
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the form module is…

  • CVE-2022-31047MedJun 14, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…

  • CVE-2021-36787MedAug 13, 2021
    risk 0.28cvss 5.4epss 0.01

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

  • CVE-2021-36785MedAug 13, 2021
    risk 0.28cvss 5.4epss 0.01

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.

  • CVE-2021-32767MedJul 20, 2021
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log level debug, which is not the default…

  • CVE-2021-21365MedApr 27, 2021
    risk 0.28cvss 5.4epss 0.01

    Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. Users of the extension, who have overwritten the affected…

  • CVE-2020-15517MedJul 7, 2020
    risk 0.28cvss 5.4epss 0.01

    The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.

  • CVE-2010-3673MedNov 5, 2019
    risk 0.28cvss 5.3epss 0.01

    TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.

  • CVE-2010-3667MedNov 4, 2019
    risk 0.28cvss 5.3epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

  • CVE-2010-3666MedNov 4, 2019
    risk 0.28cvss 5.3epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.

  • CVE-2015-8759MedJan 8, 2016
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.

  • CVE-2015-8756MedJan 8, 2016
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-77132MedSep 8, 2026
    risk 0.27cvss —epss 0.00

    It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted…

  • CVE-2026-47352MedJun 9, 2026
    risk 0.27cvss —epss 0.00

    Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51,…

  • CVE-2026-47351MedJun 9, 2026
    risk 0.27cvss —epss 0.00

    Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30…

  • CVE-2026-47350MedJun 9, 2026
    risk 0.27cvss —epss 0.00

    Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3.

  • CVE-2026-47349MedJun 9, 2026
    risk 0.27cvss —epss 0.00

    Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

  • CVE-2026-47347MedJun 9, 2026
    risk 0.27cvss —epss 0.00

    Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out…

  • CVE-2024-45232MedAug 29, 2024
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An unauthenticated attacker can use this to display the user-submitted data of all…

  • CVE-2024-34358MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.00

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query…

  • CVE-2026-47348MedJun 9, 2026
    risk 0.26cvss —epss 0.00

    Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper…

  • CVE-2026-47345MedJun 8, 2026
    risk 0.26cvss —epss 0.00

    Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

  • CVE-2024-25119MedFeb 13, 2024
    risk 0.25cvss 4.9epss 0.00

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the editing forms of the TYPO3 Install Tool user interface. This allowed attackers to utilize the value to…

  • CVE-2023-30451MedDec 25, 2023
    risk 0.25cvss 4.9epss 0.01

    In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][base…

  • CVE-2025-47937LowMay 20, 2025
    risk 0.24cvss 3.7epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction…

Page 4 of 13