📦 Typo3

by Typo3

🔍 What is Typo3?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59022

HIGH CVSS 8.1 Jan 13, 2026

This vulnerability allows backend users with access to the recycler module to delete arbitrary data from any database table defined in TYPO3's TCA, regardless of permissions. Attackers can purge criti...

CVE-2026-0859

HIGH CVSS 7.8 Jan 13, 2026

This CVE describes a deserialization vulnerability in TYPO3 CMS mail file spool functionality. Local users with write access to the spool directory can craft malicious files that execute arbitrary PHP...

CVE-2025-59017

HIGH CVSS 8.8 Sep 9, 2025

This vulnerability allows authenticated backend users in TYPO3 CMS to bypass authorization checks and directly access AJAX backend routes they shouldn't have permission to use. It affects TYPO3 CMS in...

CVE-2025-47940

HIGH CVSS 7.2 May 20, 2025

This vulnerability allows TYPO3 administrator-level backend users without system maintainer privileges to escalate their privileges and gain system maintainer access. It affects TYPO3 installations st...

CVE-2024-55924

HIGH CVSS 8.0 Jan 14, 2025

This CSRF vulnerability in TYPO3's backend allows attackers to trick authenticated backend users into executing unauthorized actions via malicious links. When combined with specific misconfigurations,...

CVE-2024-55921

HIGH CVSS 7.5 Jan 14, 2025

This CSRF vulnerability in TYPO3's backend allows attackers to trick authenticated backend users into performing unauthorized actions via malicious links. When combined with misconfigured security set...

CVE-2024-22188

HIGH CVSS 7.2 Mar 5, 2024

This CVE describes a command injection vulnerability in TYPO3's Install Tool that allows authenticated admin users with system maintainer privileges to execute arbitrary shell commands with web server...

CVE-2024-25121

HIGH CVSS 7.1 Feb 13, 2024

This vulnerability in TYPO3 allows authenticated backend users to access files in the fallback storage via the File Abstraction Layer, potentially exposing sensitive file names and contents. It affect...

CVE-2021-21355

HIGH CVSS 8.6 Mar 23, 2021

This vulnerability allows unauthenticated attackers to upload arbitrary files with any extension to TYPO3 CMS servers. It affects TYPO3 installations using Extbase MVC framework with FileReference dom...

CVE-2025-59021

MEDIUM CVSS 6.4 Jan 13, 2026

This CVE describes an authorization bypass vulnerability in TYPO3 CMS where backend users with redirect module access and write permissions could manipulate any redirect record without proper mount re...

CVE-2025-59020

MEDIUM CVSS 6.5 Jan 13, 2026

This vulnerability allows authenticated TYPO3 backend users with write permissions to bypass field-level access controls during record creation. By exploiting the defVals parameter, attackers can inse...

CVE-2025-59019

MEDIUM CVSS 4.3 Sep 9, 2025

This vulnerability allows authenticated backend users in TYPO3 CMS to download CSV files containing data from database tables they shouldn't have access to, specifically from web mounts they lack perm...

CVE-2025-59015

MEDIUM CVSS 6.5 Sep 9, 2025

This vulnerability in TYPO3 CMS's password generation component uses a predictable three-character prefix, reducing randomness and making brute-force attacks against user passwords significantly faste...

CVE-2025-59016

MEDIUM CVSS 4.3 Sep 9, 2025

This vulnerability allows authenticated backend users in TYPO3 CMS to obtain sensitive file path information through error messages when file operations fail. It affects TYPO3 installations with vulne...

CVE-2025-59013

MEDIUM CVSS 6.1 Sep 9, 2025

An open-redirect vulnerability in TYPO3 CMS's GeneralUtility::sanitizeLocalUrl function allows attackers to redirect users to malicious external websites by supplying manipulated URLs. This enables ph...

CVE-2025-7900

MEDIUM CVSS 6.5 Jul 22, 2025

The femanager extension for TYPO3 contains an Insecure Direct Object Reference vulnerability that allows attackers to modify user data without proper authorization. This affects websites running vulne...

CVE-2025-47939

MEDIUM CVSS 5.4 May 20, 2025

This vulnerability in TYPO3's file management module allows backend users to upload potentially harmful files like executables or files with mismatched extensions/MIME types. While these files aren't ...

CVE-2024-55922

MEDIUM CVSS 5.4 Jan 14, 2025

This CSRF vulnerability in TYPO3's backend allows attackers to manipulate or delete form definitions when authenticated backend users interact with malicious URLs. It affects TYPO3 installations with ...

CVE-2024-55945

MEDIUM CVSS 4.3 Jan 14, 2025

This CSRF vulnerability in TYPO3's backend user interface allows attackers to trick authenticated backend users into performing unauthorized state-changing actions via malicious links. The vulnerabili...

CVE-2024-55894

MEDIUM CVSS 4.3 Jan 14, 2025

This CSRF vulnerability in TYPO3's backend user interface allows attackers to perform unauthorized password resets or session terminations for other backend users. It affects TYPO3 installations with ...

CVE-2024-55892

MEDIUM CVSS 4.8 Jan 14, 2025

This vulnerability in TYPO3's URI parsing component allows attackers to bypass host validation checks when processing externally provided URLs. This can lead to open redirect attacks (redirecting user...

CVE-2024-34358

MEDIUM CVSS 5.3 May 14, 2024

This vulnerability in TYPO3's ShowImageController allows attackers to trigger unlimited thumbnail generation by manipulating the 'frame' parameter without proper HMAC validation. It affects TYPO3 inst...

CVE-2024-34356

MEDIUM CVSS 5.4 May 14, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in TYPO3's form manager backend module. It allows authenticated backend users with form module access to inject malicious scripts that cou...