TYPO3 CMS
37 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for TYPO3 CMS, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
TYPO3 CMS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 7 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 4 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 13 |
| 2026-07 | 1 |
| 2026-08 | 1 |
| 2026-09 | 2 |
Severity
How the 37 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High9
- Medium9
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting TYPO3 CMS.
- CVE-2026-77132TYPO3 CMS - Information Disclosure via Backend Localization Wizard—
- CVE-2026-85400TYPO3 CMS - Missing Authorization in lowlevel commands—
- CVE-2026-19418TYPO3 CMS - Broken Access Control in Backend and Install Tool—
- CVE-2026-15305TYPO3 CMS - Unrestricted File Upload in Form Framework—
- CVE-2026-49742TYPO3 CMS - Broken Access Control in Media Module—
- CVE-2026-49741TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework—
- CVE-2026-49740TYPO3 CMS - Insecure Deserialization in Core API—
- CVE-2026-49738TYPO3 CMS - Broken Access Control in File Abstraction Layer—
- CVE-2026-47352TYPO3 CMS - Broken Access Control in Backend API—
- CVE-2026-47351TYPO3 CMS - Broken Access Control in Clipboard—
- CVE-2026-47350TYPO3 CMS - Broken Access Control in DataHandler—
- CVE-2026-47349TYPO3 CMS - Broken Access Control in Recycler—
- CVE-2026-47348TYPO3 CMS - Cross-Site Scripting in Indexed Search—
- CVE-2026-47347TYPO3 CMS - Open Redirect in Core Utilities—
- CVE-2026-47346TYPO3 CMS - Broken Access Control in Form Framework—
Product grouping is registry-driven, with AI assist and human review. How it works