Typo3.cms
This hub aggregates every CVE we track for Typo3.cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
116
CVEs tracked
3
Critical
23
High
0
In CISA KEV
Severity distribution
MEDIUM79HIGH23LOW11CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Typo3.cms.
- CVE-2023-24814Persisted Cross-Site Scripting in Frontend Rendering in typo38.8
- CVE-2022-23504TYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration5.7
- CVE-2022-23503TYPO3 vulnerable to Arbitrary Code Execution via Form Framework7.5
- CVE-2022-23502TYPO3 contains Insufficient Session Expiration after Password Reset5.4
- CVE-2022-23501TYPO3 vulnerable to Improper Authentication in Frontend Login5.9
- CVE-2022-23500TYPO3 subject to Uncontrolled Recursion resulting in Denial of Service5.9
- CVE-2022-47406An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for th...5.4
- CVE-2022-23499Cross-Site Scripting Protection bypass in HTML Sanitizer6.1
- CVE-2022-36105User Enumeration via Response Timing in TYPO35.3
- CVE-2022-36106Missing check for expiration time of password reset token in TYPO35.4
- CVE-2022-36107Stored Cross-Site Scripting via FileDumpController6.5
- CVE-2022-36104Denial of Service via Page Error Handling in TYPO3/cms5.9
- CVE-2022-36108Cross-Site Scripting in typo3/cms-core6.5
- CVE-2022-36020Bypass of Cross-Site Scripting Protection in typo3/html-sanitizer6.1
- CVE-2022-31050Insufficient Session Expiration in TYPO3 Admin Tool6.0
Product normalization is registry-driven with AI assist and human review. How it works