Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-6553 Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be… TYPO3 Patch available Fix from $1,9502026-04-21 HIGH 8.1 CVE-2025-59022 Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether th… TYPO3 10.4.55 / 11.5.49+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-0859 TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized du… TYPO3 10.4.55 / 11.5.49+ Fix from $1,9502026-01-13 MEDIUM 6.4 CVE-2025-59021 Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect r… TYPO3 10.4.55 / 11.5.49+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2025-59020 By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the… TYPO3 10.4.55 / 11.5.49+ Fix from $1,6002026-01-13 HIGH 8.8 CVE-2025-59017 Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13… TYPO3 9.5.55 / 10.4.54+ Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-59015 A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, … TYPO3 12.4.37 / 13.4.18+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-59018 Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1… TYPO3 9.5.55 / 10.4.54+ Fix from $1,6002025-09-09 MEDIUM 6.1 CVE-2025-59013 An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.… TYPO3 9.5.55 / 10.4.54+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-7900 The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema… TYPO3 after 8.3.0 Fix from $1,6002025-07-22 HIGH 7.2 CVE-2025-47941 TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13… TYPO3 12.4.31 / 13.4.12+ Fix from $1,9502025-05-20 HIGH 7.2 CVE-2025-47940 TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.3… TYPO3 10.4.50 / 11.5.44+ Fix from $1,9502025-05-20 MEDIUM 5.4 CVE-2025-47939 TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has histori… TYPO3 9.5.51 / 10.4.50+ Fix from $1,6002025-05-20 MEDIUM 5.3 CVE-2025-47937 TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 … TYPO3 9.5.51 / 10.4.50+ Fix from $1,6002025-05-20 HIGH 8.0 CVE-2024-55924 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 11.5.42+ Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2024-55945 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 11.5.42+ Fix from $1,6002025-01-14 MEDIUM 5.4 CVE-2024-55922 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,6002025-01-14 HIGH 8.8 CVE-2024-55921 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,9502025-01-14 MEDIUM 5.4 CVE-2024-55894 TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi… TYPO3 10.4.48 / 11.5.42+ Fix from $1,6002025-01-14 MEDIUM 6.1 CVE-2024-55892 TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g.… TYPO3 9.5.49 / 10.4.48+ Fix from $1,6002025-01-14 MEDIUM 5.3 CVE-2024-55891 TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c… TYPO3 Mitigation only Fix from $1,6002025-01-14 MEDIUM 5.4 CVE-2024-34357 TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS… TYPO3 9.5.48 / 10.4.45+ Fix from $1,6002024-05-14 MEDIUM 5.3 CVE-2024-34358 TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS… TYPO3 9.5.48 / 10.4.45+ Fix from $1,6002024-05-14 MEDIUM 5.4 CVE-2024-34355 TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to… TYPO3 13.1.1+ Fix from $1,6002024-05-14 MEDIUM 5.4 CVE-2024-34356 TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS… TYPO3 9.5.48 / 10.4.45+ Fix from $1,6002024-05-14 HIGH 7.2 CVE-2024-22188 TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o… TYPO3 8.7.57 / 9.5.46+ Fix from $1,9502024-03-05 HIGH 7.1 CVE-2024-25121 TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstra… TYPO3 8.7.57 / 9.5.46+ Fix from $1,9502024-02-13 MEDIUM 6.5 CVE-2024-25118 TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms… TYPO3 8.7.57 / 9.5.46+ Fix from $1,6002024-02-13 MEDIUM 5.4 CVE-2023-47127 TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two diff… TYPO3 8.7.55 / 9.5.44+ Fix from $1,6002023-11-14 MEDIUM 5.3 CVE-2023-47126 TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone i… TYPO3 12.4.8+ Fix from $1,6002023-11-14