typo3/cms-backend vulnerabilities
CVEs whose affected-version data names the typo3/cms-backend package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-77132Medium· 5.3It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content ele…
▾ SunlitTYPO3 · typo3/cms-backendEPSS 0.41%via NVD
CVE-2026-19418HighTYPO3 CMS - Broken Access Control in Backend and Install Tool
TYPO3 CMS - Broken Access Control in Backend and Install Tool
▾ Twilighttypo3 · typo3/cms-backendEPSS 0.21%via GHSA
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
TYPO3 CMS: Broken Access Control in Media Module
▾ Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
TYPO3 CMS has Broken Access Control in Backend API
▾ Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA