Vulnerabilities in TYPO3

175 results
Vexday analysis

O ecossistema de vulnerabilidades do TYPO3 acumula 141 CVEs catalogadas, com 24 registros surgidos nos últimos 90 dias, o que indica um ritmo contínuo de descobertas que merece acompanhamento. Nenhuma das vulnerabilidades está listada no catálogo CISA KEV e não há PoCs públicas conhecidas, colocando a taxa de exploração ativa abaixo da média geral do catálogo — um indicador favorável, mas não suficiente para reduzir a vigilância. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que exige atenção especial em implementações que aceitam entrada de usuários sem sanitização adequada. A CVE mais perigosa atualmente rastreada é CVE-2026-46725, com score EPSS de 0,0231, sugerindo probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o contexto das 2 vulnerabilidades de severidade crítica presentes no portfólio.

CVE-2023-37905MEDIUMCross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-pluginEPSS 0.6%CVE-2023-47127MEDIUMWeak Authentication in Session Handling in typo3/cms-coreEPSS 0.6%CVE-2024-25118MEDIUMInformation Disclosure of Hashed Passwords in TYPO3 Backend FormsEPSS 0.6%CVE-2026-77136CRITICALServer-Side Template Injection in extension "powermail" (powermail)EPSS 0.6%CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2020-11065MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2020-11064MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2022-23504MEDIUMTYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site ConfigurationEPSS 0.5%CVE-2023-38500MEDIUMBy-passing Cross-Site Scripting Protection in HTML SanitizerEPSS 0.5%CVE-2024-34356MEDIUMTYPO3 vulnerable to Cross-Site Scripting in the Form Manager ModuleEPSS 0.5%CVE-2024-34357MEDIUMTYPO3 vulnerable to Cross-Site Scripting in ShowImageControllerEPSS 0.5%CVE-2024-25121HIGHImproper Access Control Persisting File Abstraction Layer Entities via Data Handler in TYPO3EPSS 0.5%CVE-2022-23501MEDIUMTYPO3 vulnerable to Improper Authentication in Frontend LoginEPSS 0.5%CVE-2024-34358MEDIUMTYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageControllerEPSS 0.5%CVE-2025-47941HIGHTYPO3 Has Broken Authentication in Backend MFAEPSS 0.4%CVE-2026-85400HIGHTYPO3 CMS - Missing Authorization in lowlevel commandsEPSS 0.4%CVE-2022-23499MEDIUMCross-Site Scripting Protection bypass in HTML SanitizerEPSS 0.4%CVE-2025-47940HIGHTYPO3 CMS Vulnerable to Privilege Escalation to System MaintainerEPSS 0.4%CVE-2025-12998HIGHBroken Authentication in extension “Modules” (modules)EPSS 0.4%CVE-2025-59022HIGHTYPO3 CMS Allows Broken Access Control in Recycler ModuleEPSS 0.4%