Vulnerabilidades en typo3
175 resultadosAnálisis Vexday
TYPO3 apresenta exposição mínima com apenas 1 CVE registrada na base, sem incidentes de exploração ativa (KEV) ou vulnerabilidades críticas. A fraqueza identificada é XSS (CWE-79), com risco não recente, mantendo o fornecedor em postura de baixo risco operacional no curto prazo.
CVE-2026-46723MEDIUMInformation Disclosure in extension "Faceted Search" (ke_search)EPSS 0.3%CVE-2025-59020MEDIUMTYPO3 CMS Allows Broken Access Control in Edit Document ControllerEPSS 0.3%CVE-2026-49742HIGHTYPO3 CMS - Broken Access Control in Media ModuleEPSS 0.3%CVE-2026-46722MEDIUMXML External Entity Injection in extension "Faceted Search" (ke_search)EPSS 0.3%CVE-2024-47780LOWInformation Disclosure in TYPO3 Page TreeEPSS 0.3%CVE-2026-77144HIGHBroken Access Control in extension "Events 2" (events2)EPSS 0.3%CVE-2025-59017MEDIUMBroken Access Control in Backend AJAX RoutesEPSS 0.3%CVE-2026-47347MEDIUMTYPO3 CMS - Open Redirect in Core UtilitiesEPSS 0.3%CVE-2026-77139MEDIUMPath Traversal in extension "Mask" (mask)EPSS 0.3%CVE-2025-59014MEDIUMDenial of Service in TYPO3 Bookmark ToolbarEPSS 0.3%CVE-2025-47937LOWTYPO3 Vulnerable to Information Disclosure via DBAL Restriction HandlingEPSS 0.3%CVE-2025-59018HIGHInformation Disclosure in Workspaces ModuleEPSS 0.3%CVE-2025-48202MEDIUMThe femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.3%CVE-2026-47344LOWTYPO3 HTML Sanitizer allows Cross-Site ScriptingEPSS 0.3%CVE-2025-7899MEDIUMInsecure Direct Object Reference in extension "powermail" (powermail)EPSS 0.3%CVE-2025-59021MEDIUMTYPO3 CMS Allows Broken Access Control in Redirects ModuleEPSS 0.3%CVE-2026-47348MEDIUMTYPO3 CMS - Cross-Site Scripting in Indexed SearchEPSS 0.3%CVE-2023-50462MEDIUMAn issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specifiEPSS 0.3%CVE-2025-47938LOWTYPO3 Vulnerable to Unverified Password Change for Backend UsersEPSS 0.3%CVE-2025-47936LOWTYPO3 Vulnerable to Server Side Request Forgery via WebhooksEPSS 0.3%