VulnSea

typo3 has 30 CVEs on record. Cadence is steady at roughly 15 per quarter. The busiest recent month was June 2026 with 15. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (11) and CWE-863 (5). Most affected products: typo3/cms-core (13), apache-solr-for-typo3/solr (5), femanager (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
15 prev 15

Products

  • typo3/cms-core 13
  • apache-solr-for-typo3/solr 5
  • femanager 3
  • typo3/cms-backend 2
  • typo3/html-sanitizer 2
  • codingms/modules 1
30
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

typo3 vulnerabilities

CVEs affecting typo3, newest first. Open any entry for full detail, references, and exploit status.

30 CVEsRSS

CVE-2023-50461High· 8.8
1w ago

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured …

TwilightTYPO3 · direct_mailEPSS 0.33%via NVD
CVE-2023-50460Medium· 5.4
1w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any f…

SunlitTYPO3 · femanagerEPSS 0.24%via NVD
CVE-2023-45023Medium· 4.2
1w ago

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

SunlitTYPO3 · femanagerEPSS 0.14%via NVD
CVE-2023-50462Medium· 5.3
1w ago

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to…

SunlitTYPO3 · content_consentEPSS 0.27%via NVD
CVE-2023-50459Medium· 5.4
1w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend user…

SunlitTYPO3 · femanagerEPSS 0.24%via NVD
CVE-2026-85400High· 7.5
2w ago

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is nor…

TwilightTYPO3 · typo3/cms-lowlevelEPSS 0.44%via NVD
CVE-2026-77132Medium· 5.3
2w ago

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content ele…

SunlitTYPO3 · typo3/cms-backendEPSS 0.41%via NVD
CVE-2026-19418High
3w ago

TYPO3 CMS - Broken Access Control in Backend and Install Tool

TYPO3 CMS - Broken Access Control in Backend and Install Tool

Twilighttypo3 · typo3/cms-backendEPSS 0.21%via GHSA
CVE-2026-15305Medium
3w ago

TYPO3 CMS - Unrestricted File Upload in Form Framework

TYPO3 CMS - Unrestricted File Upload in Form Framework

Sunlittypo3 · typo3/cms-formEPSS 0.25%via GHSA
CVE-2026-56096Medium· 6.3PoC
4w ago

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to e…

TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.33%via NVD
CVE-2026-56095High· 7.7
4w ago

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.25%via NVD
CVE-2026-56093Medium· 6.3
4w ago

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retriev…

SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.24%via NVD
CVE-2026-56092High· 7.6
4w ago

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass exten…

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass exten…

TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.22%via NVD
CVE-2026-56094Medium· 6.3
4w ago

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a…

SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.26%via NVD
CVE-2026-77127Medium· 6.0
4w ago

Information Disclosure in extension "Modules" (modules)

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and…

SunlitTYPO3 · codingms/modulesEPSS 0.26%via CVEORG
CVE-2026-47344Low
3mo ago

TYPO3 HTML Sanitizer allows Cross-site Scripting

TYPO3 HTML Sanitizer allows Cross-site Scripting

Sunlittypo3 · typo3/html-sanitizerEPSS 0.28%via GHSA
CVE-2026-47348Medium
3mo ago

TYPO3 CMS has Cross-Site Scripting in Indexed Search

TYPO3 CMS has Cross-Site Scripting in Indexed Search

Sunlittypo3 · typo3/cms-coreEPSS 0.27%via GHSA
CVE-2026-47351Medium
3mo ago

TYPO3 CMS: Broken Access Control in Media Module

TYPO3 CMS: Broken Access Control in Media Module

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47352Medium
3mo ago

TYPO3 CMS has Broken Access Control in Backend API

TYPO3 CMS has Broken Access Control in Backend API

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-49738Low
3mo ago

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

Sunlittypo3 · typo3/cms-coreEPSS 0.36%via GHSA
CVE-2026-49740Medium
3mo ago

TYPO3 CMS has Insecure Deserialization via Core API

TYPO3 CMS has Insecure Deserialization via Core API

Sunlittypo3 · typo3/cms-coreEPSS 0.21%via GHSA
CVE-2026-49742High
3mo ago

TYPO3 CMS has Broken Access Control in its Media Module

TYPO3 CMS has Broken Access Control in its Media Module

Twilighttypo3 · typo3/cms-coreEPSS 0.31%via GHSA
CVE-2026-47346High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.25%via GHSA
CVE-2026-47350Medium
3mo ago

TYPO3 CMS has Broken Access Control in its DataHandler

TYPO3 CMS has Broken Access Control in its DataHandler

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-49741High
3mo ago

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47345Medium
3mo ago

TYPO3 HTML Sanitizer allows Cross-site Scripting

TYPO3 HTML Sanitizer allows Cross-site Scripting

Sunlittypo3 · typo3/html-sanitizerEPSS 0.37%via GHSA
CVE-2026-47343High
3mo ago

TYPO3 CMS: Destructive Actions on File Mount Folders

TYPO3 CMS: Destructive Actions on File Mount Folders

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-47347Medium
3mo ago

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

Sunlittypo3 · typo3/cms-coreEPSS 0.29%via GHSA
CVE-2026-47349Medium
3mo ago

TYPO3 CMS has Broken Access Control in the Recycler Module

TYPO3 CMS has Broken Access Control in the Recycler Module

Sunlittypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-11607High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
typo3 vulnerabilities (CVEs) · VulnSea