Typo3 cms
This hub aggregates every CVE we track for Typo3 cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
37
CVEs tracked
0
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM9LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
7
0
0
0
4
0
0
1
0
13
1
1
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Typo3 cms.
- CVE-2026-77132TYPO3 CMS - Information Disclosure via Backend Localization Wizard
- CVE-2026-85400TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-19418TYPO3 CMS - Broken Access Control in Backend and Install Tool
- CVE-2026-15305TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2026-49742TYPO3 CMS - Broken Access Control in Media Module
- CVE-2026-49741TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework
- CVE-2026-49740TYPO3 CMS - Insecure Deserialization in Core API
- CVE-2026-49738TYPO3 CMS - Broken Access Control in File Abstraction Layer
- CVE-2026-47352TYPO3 CMS - Broken Access Control in Backend API
- CVE-2026-47351TYPO3 CMS - Broken Access Control in Clipboard
- CVE-2026-47350TYPO3 CMS - Broken Access Control in DataHandler
- CVE-2026-47349TYPO3 CMS - Broken Access Control in Recycler
- CVE-2026-47348TYPO3 CMS - Cross-Site Scripting in Indexed Search
- CVE-2026-47347TYPO3 CMS - Open Redirect in Core Utilities
- CVE-2026-47346TYPO3 CMS - Broken Access Control in Form Framework
Product normalization is registry-driven with AI assist and human review. How it works