CVE-2026-47348Medium▾ SunlitTYPO3 CMS has Cross-Site Scripting in Indexed Search
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability.
Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it.
typo3/cms-core >= 13.0.0, < 13.4.31typo3/cms-core >= 14.0.0, < 14.3.3typo3/cms-indexed-search >= 13.0.0, < 13.4.31typo3/cms-indexed-search >= 14.0.0, < 14.3.3Upgrade to a patched release:
typo3/cms-core 13.4.31typo3/cms-core 14.3.3typo3/cms-indexed-search 13.4.31typo3/cms-indexed-search 14.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47344LowTYPO3 HTML Sanitizer allows Cross-site Scripting
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
CVE-2026-49738LowTYPO3 CMS has Broken Access Control in its File Abstraction Layer
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module