typo3/cms-core vulnerabilities
CVEs whose affected-version data names the typo3/cms-core package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
14 CVEsRSS
CVE-2026-19418HighTYPO3 CMS - Broken Access Control in Backend and Install Tool
TYPO3 CMS - Broken Access Control in Backend and Install Tool
CVE-2026-47348MediumTYPO3 CMS has Cross-Site Scripting in Indexed Search
TYPO3 CMS has Cross-Site Scripting in Indexed Search
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
TYPO3 CMS: Broken Access Control in Media Module
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
TYPO3 CMS has Broken Access Control in Backend API
CVE-2026-49738LowTYPO3 CMS has Broken Access Control in its File Abstraction Layer
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
TYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module
TYPO3 CMS has Broken Access Control in its Media Module
CVE-2026-47346HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
CVE-2026-47350MediumTYPO3 CMS has Broken Access Control in its DataHandler
TYPO3 CMS has Broken Access Control in its DataHandler
CVE-2026-49741HighTYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
CVE-2026-47343HighTYPO3 CMS: Destructive Actions on File Mount Folders
TYPO3 CMS: Destructive Actions on File Mount Folders
CVE-2026-47347MediumTYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
CVE-2026-47349MediumTYPO3 CMS has Broken Access Control in the Recycler Module
TYPO3 CMS has Broken Access Control in the Recycler Module
CVE-2026-11607HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework