CVE-2026-47347Medium▾ SunlitTYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks.
Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
TYPO3 CMS thanks Alexandre Romao for reporting this issue, and TYPO3 core & security team member Benjamin Franzke for fixing it.
typo3/cms-core < 10.4.57typo3/cms-core >= 11.0.0, < 11.5.51typo3/cms-core >= 12.0.0, < 12.4.46typo3/cms-core >= 13.0.0, < 13.4.31typo3/cms-core >= 14.0.0, < 14.3.3Upgrade to a patched release:
typo3/cms-core 10.4.57typo3/cms-core 11.5.51typo3/cms-core 12.4.46typo3/cms-core 13.4.31typo3/cms-core 14.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47348MediumTYPO3 CMS has Cross-Site Scripting in Indexed Search
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
CVE-2026-49738LowTYPO3 CMS has Broken Access Control in its File Abstraction Layer
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module