VulnSea

typo3/cms-core vulnerabilities

CVEs whose affected-version data names the typo3/cms-core package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-19418High
3w ago

TYPO3 CMS - Broken Access Control in Backend and Install Tool

TYPO3 CMS - Broken Access Control in Backend and Install Tool

Twilighttypo3 · typo3/cms-backendEPSS 0.21%via GHSA
CVE-2026-47348Medium
3mo ago

TYPO3 CMS has Cross-Site Scripting in Indexed Search

TYPO3 CMS has Cross-Site Scripting in Indexed Search

Sunlittypo3 · typo3/cms-coreEPSS 0.27%via GHSA
CVE-2026-47351Medium
3mo ago

TYPO3 CMS: Broken Access Control in Media Module

TYPO3 CMS: Broken Access Control in Media Module

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47352Medium
3mo ago

TYPO3 CMS has Broken Access Control in Backend API

TYPO3 CMS has Broken Access Control in Backend API

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-49738Low
3mo ago

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

Sunlittypo3 · typo3/cms-coreEPSS 0.36%via GHSA
CVE-2026-49740Medium
3mo ago

TYPO3 CMS has Insecure Deserialization via Core API

TYPO3 CMS has Insecure Deserialization via Core API

Sunlittypo3 · typo3/cms-coreEPSS 0.21%via GHSA
CVE-2026-49742High
3mo ago

TYPO3 CMS has Broken Access Control in its Media Module

TYPO3 CMS has Broken Access Control in its Media Module

Twilighttypo3 · typo3/cms-coreEPSS 0.31%via GHSA
CVE-2026-47346High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.25%via GHSA
CVE-2026-47350Medium
3mo ago

TYPO3 CMS has Broken Access Control in its DataHandler

TYPO3 CMS has Broken Access Control in its DataHandler

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-49741High
3mo ago

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47343High
3mo ago

TYPO3 CMS: Destructive Actions on File Mount Folders

TYPO3 CMS: Destructive Actions on File Mount Folders

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47347Medium
3mo ago

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

Sunlittypo3 · typo3/cms-coreEPSS 0.29%via GHSA
CVE-2026-47349Medium
3mo ago

TYPO3 CMS has Broken Access Control in the Recycler Module

TYPO3 CMS has Broken Access Control in the Recycler Module

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-11607High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
typo3/cms-core vulnerabilities (CVEs) · VulnSea