Typo3/cms
This hub aggregates every CVE we track for Typo3/cms, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
188
CVEs tracked
3
Critical
23
High
0
In CISA KEV
Severity distribution
MEDIUM79HIGH23LOW11CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Typo3/cms.
- GHSA-f3wf-q4fj-3gxfTYPO3 Denial of Service in Online Media Asset Handling
- GHSA-6487-3qvg-8px9TYPO3 Information Disclosure in Install Tool
- GHSA-f777-f784-36gmTYPO3 Security Misconfiguration in Install Tool Cookie
- GHSA-2rcw-9hrm-8q7qTYPO3 Cross-Site Scripting in Frontend User Login
- GHSA-7q33-hxwj-7p8vTYPO3 Cross-Site Scripting in Backend Modal Component
- GHSA-8m6j-p5jv-v69wTYPO3 Cross-Site Scripting in Online Media Asset Rendering
- GHSA-8h4m-r4wm-xj7rTYPO3 Arbitrary Code Execution via File List Module
- GHSA-g585-crjf-vhwqTYPO3 Denial of Service in Frontend Record Registration
- GHSA-f624-8hfq-5fh3TYPO3 Information Disclosure of Installed Extensions
- GHSA-v8m4-3w37-ghxxTYPO3 Cross-Site Scripting in Form Framework validation handling
- GHSA-4h5c-5g25-v7fhTYPO3 Cross-Site Scripting in Form Framework
- GHSA-c5mj-39cf-3pp5TYPO3 Security Misconfiguration for Backend User Accounts
- GHSA-xgmx-j3hv-jh9xTYPO3 Cross-Site Scripting in Link Handling
- GHSA-772m-43f3-hmf8TYPO3 Broken Access Control in Localization Handling
- GHSA-g7hw-jh4p-75wrTYPO3 Cross-Site Scripting in Filelist Module
Product normalization is registry-driven with AI assist and human review. How it works