VulnSea

apache-solr-for-typo3/solr vulnerabilities

CVEs whose affected-version data names the apache-solr-for-typo3/solr package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-56096Medium· 6.3PoC
1mo ago

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to e…

▾ TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.43%via NVD
CVE-2026-56095High· 7.7
1mo ago

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

▾ TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.32%via NVD
CVE-2026-56093Medium· 6.3
1mo ago

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retriev…

▾ SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.31%via NVD
CVE-2026-56092High· 7.6
1mo ago

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass exten…

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass exten…

▾ TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.29%via NVD
CVE-2026-56094Medium· 6.3
1mo ago

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a…

▾ SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.33%via NVD
apache-solr-for-typo3/solr vulnerabilities (CVEs) · VulnSea