Vulnerabilities in typo3

175 results
Vexday analysis

TYPO3 apresenta exposição mínima com apenas 1 CVE registrada na base, sem incidentes de exploração ativa (KEV) ou vulnerabilidades críticas. A fraqueza identificada é XSS (CWE-79), com risco não recente, mantendo o fornecedor em postura de baixo risco operacional no curto prazo.

CVE-2025-59022HIGHTYPO3 CMS Allows Broken Access Control in Recycler ModuleEPSS 0.4%CVE-2026-77132MEDIUMTYPO3 CMS - Information Disclosure via Backend Localization WizardEPSS 0.4%CVE-2026-46724MEDIUMPath Traversal in extension "Faceted Search" (ke_search)EPSS 0.4%CVE-2022-23502MEDIUMTYPO3 contains Insufficient Session Expiration after Password ResetEPSS 0.4%CVE-2026-8727HIGHRemote Code Execution in extension "Site Crawler" (crawler)EPSS 0.4%CVE-2026-8726HIGHSQL Injection in extension "News system" (news)EPSS 0.4%CVE-2026-77128MEDIUMBroken Access Control in extension "Event management and registration" (sf_event_mgt)EPSS 0.4%CVE-2026-47345MEDIUMTYPO3 HTML Sanitizer allows Cross-Site ScriptingEPSS 0.4%CVE-2024-25119MEDIUMInformation Disclosure of Encryption Key in TYPO3 Install ToolEPSS 0.4%CVE-2026-46721MEDIUMBroken Access Control in extension "Frontend User Registration" (sf_register)EPSS 0.4%CVE-2024-55921HIGHCross-Site Request Forgery in Extension Manager Module in TYPO3EPSS 0.4%CVE-2026-49738LOWTYPO3 CMS - Broken Access Control in File Abstraction LayerEPSS 0.4%CVE-2025-48205HIGHThe sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.4%CVE-2025-48207HIGHThe reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.4%CVE-2025-48201HIGHThe ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.EPSS 0.4%CVE-2025-10316LOWCross-Site Scripting in extension "Form to Database" (form_to_database)EPSS 0.3%CVE-2026-56096MEDIUMInformation Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)EPSS 0.3%CVE-2026-8827HIGHSQL Injection in extension "Address List" (tt_address)EPSS 0.3%CVE-2023-50461HIGHAn issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the exteEPSS 0.3%CVE-2024-55891LOWInformation Disclosure via Exception Handling/Logger in TYPO3EPSS 0.3%