TYPO3 CMS是TYPO3开源的一个内容管理系统。 TYPO3 CMS 14.0.0至14.3.3版本存在SQL注入漏洞,该漏洞源于具有form_definition数据库表写入权限的后端用户能够通过DataHandler直接创建、更新或删除表单定义记录,绕过了表单框架的持久性验证和权限检查,允许注入任意表单配置,重新启用TYPO3-CORE-SA-2018-003中解决的攻击向量,包括SQL注入和权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47347 | TYPO3 CMS - Open Redirect in Core Utilities | |
| CVE-2026-47349 | TYPO3 CMS - Broken Access Control in Recycler | |
| CVE-2026-47350 | TYPO3 CMS - Broken Access Control in DataHandler | |
| CVE-2026-47348 | TYPO3 CMS - Cross-Site Scripting in Indexed Search | |
| CVE-2026-47352 | TYPO3 CMS - Broken Access Control in Backend API | |
| CVE-2026-47346 | TYPO3 CMS - Broken Access Control in Form Framework | |
| CVE-2026-47351 | TYPO3 CMS - Broken Access Control in Clipboard | |
| CVE-2026-47343 | TYPO3 CMS - Destructive Actions on File Mount Folders | |
| CVE-2026-11607 | TYPO3 CMS - Broken Access Control in Form Framework | |
| CVE-2026-49742 | TYPO3 CMS - Broken Access Control in Media Module | |
| CVE-2026-49738 | TYPO3 CMS - Broken Access Control in File Abstraction Layer | |
| CVE-2026-49740 | TYPO3 CMS - Insecure Deserialization in Core API |
No comments yet