Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TYPO3 CMS — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in TYPO3 CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting TYPO3 CMS, a widely used open-source content management system developed by the TYPO3 Association. It collects security flaws categorized under general web application weaknesses, covering incidents reported over the past five years. Readers can use this collection to track the vendor’s security advisories, analyze specific weakness classes, and review the product’s historical vulnerability record. The data serves as a reference for security teams assessing risk exposure in environments where TYPO3 CMS is deployed for managing website content.

Vendor: TYPO3

CVE ID Title CVSS Severity Published
CVE-2026-77132 TYPO3 CMS - Information Disclosure via Backend Localization Wizard CWE-862 5.3 Medium 2026-09-08
CVE-2026-85400 TYPO3 CMS - Missing Authorization in lowlevel commands CWE-862 7.5 High 2026-09-08
CVE-2026-19418 TYPO3 CMS - Broken Access Control in Backend and Install Tool CWE-346 7.3 High 2026-08-11
CVE-2026-15305 TYPO3 CMS - Unrestricted File Upload in Form Framework CWE-351 - - 2026-07-14
CVE-2026-49742 TYPO3 CMS - Broken Access Control in Media Module CWE-22 - - 2026-06-09
CVE-2026-49741 TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework CWE-862 - - 2026-06-09
CVE-2026-49740 TYPO3 CMS - Insecure Deserialization in Core API CWE-502 - - 2026-06-09
CVE-2026-49738 TYPO3 CMS - Broken Access Control in File Abstraction Layer CWE-22 - - 2026-06-09
CVE-2026-47352 TYPO3 CMS - Broken Access Control in Backend API CWE-862 - - 2026-06-09
CVE-2026-47351 TYPO3 CMS - Broken Access Control in Clipboard CWE-862 - - 2026-06-09
CVE-2026-47350 TYPO3 CMS - Broken Access Control in DataHandler CWE-862 - - 2026-06-09
CVE-2026-47349 TYPO3 CMS - Broken Access Control in Recycler CWE-862 - - 2026-06-09
CVE-2026-47348 TYPO3 CMS - Cross-Site Scripting in Indexed Search CWE-79 - - 2026-06-09
CVE-2026-47347 TYPO3 CMS - Open Redirect in Core Utilities CWE-601 - - 2026-06-09
CVE-2026-47346 TYPO3 CMS - Broken Access Control in Form Framework CWE-178 - - 2026-06-09
CVE-2026-47343 TYPO3 CMS - Destructive Actions on File Mount Folders CWE-862 - - 2026-06-09
CVE-2026-11607 TYPO3 CMS - Broken Access Control in Form Framework CWE-862 - - 2026-06-09
CVE-2026-6553 TYPO3 CMS Stores Cleartext Password in User Settings Module CWE-312 6.5AI Medium AI 2026-04-21
CVE-2026-0859 TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool CWE-502 7.8AI High AI 2026-01-13
CVE-2025-59022 TYPO3 CMS Allows Broken Access Control in Recycler Module CWE-862 8.1AI High AI 2026-01-13
CVE-2025-59021 TYPO3 CMS Allows Broken Access Control in Redirects Module CWE-862 4.6AI Medium AI 2026-01-13
CVE-2025-59020 TYPO3 CMS Allows Broken Access Control in Edit Document Controller CWE-863 4.3AI Medium AI 2026-01-13
CVE-2025-59019 Information Disclosure via CSV Download CWE-200 6.5AI Medium AI 2025-09-09
CVE-2025-59018 Information Disclosure in Workspaces Module CWE-200 6.5AI Medium AI 2025-09-09
CVE-2025-59017 Broken Access Control in Backend AJAX Routes CWE-862 8.8AI High AI 2025-09-09
CVE-2025-59016 Information Disclosure via File Abstraction Layer CWE-209 4.3AI Medium AI 2025-09-09
CVE-2025-59015 Insufficient Entropy in Password Generation CWE-331 9.8AI Critical AI 2025-09-09
CVE-2025-59014 Denial of Service in TYPO3 Bookmark Toolbar CWE-248 4.9AI Medium AI 2025-09-09
CVE-2025-59013 Open Redirect in TYPO3 CMS CWE-601 6.1AI Medium AI 2025-09-09
CVE-2020-15098 Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS CWE-325 8.8 High 2020-07-29

All 37 known CVE vulnerabilities affecting TYPO3 CMS with full Chinese analysis, references, and POCs where available.