Vulnerabilidades em typo3
175 resultadosAnálise Vexday
TYPO3 apresenta exposição mínima com apenas 1 CVE registrada na base, sem incidentes de exploração ativa (KEV) ou vulnerabilidades críticas. A fraqueza identificada é XSS (CWE-79), com risco não recente, mantendo o fornecedor em postura de baixo risco operacional no curto prazo.
CVE-2023-37905MEDIUMCross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-pluginEPSS 0.6%CVE-2023-47127MEDIUMWeak Authentication in Session Handling in typo3/cms-coreEPSS 0.6%CVE-2024-25118MEDIUMInformation Disclosure of Hashed Passwords in TYPO3 Backend FormsEPSS 0.6%CVE-2026-77136CRITICALServer-Side Template Injection in extension "powermail" (powermail)EPSS 0.6%CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2020-11065MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2020-11064MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2022-23504MEDIUMTYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site ConfigurationEPSS 0.5%CVE-2023-38500MEDIUMBy-passing Cross-Site Scripting Protection in HTML SanitizerEPSS 0.5%CVE-2024-34356MEDIUMTYPO3 vulnerable to Cross-Site Scripting in the Form Manager ModuleEPSS 0.5%CVE-2024-34357MEDIUMTYPO3 vulnerable to Cross-Site Scripting in ShowImageControllerEPSS 0.5%CVE-2024-25121HIGHImproper Access Control Persisting File Abstraction Layer Entities via Data Handler in TYPO3EPSS 0.5%CVE-2022-23501MEDIUMTYPO3 vulnerable to Improper Authentication in Frontend LoginEPSS 0.5%CVE-2024-34358MEDIUMTYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageControllerEPSS 0.5%CVE-2025-47941HIGHTYPO3 Has Broken Authentication in Backend MFAEPSS 0.4%CVE-2026-85400HIGHTYPO3 CMS - Missing Authorization in lowlevel commandsEPSS 0.4%CVE-2022-23499MEDIUMCross-Site Scripting Protection bypass in HTML SanitizerEPSS 0.4%CVE-2025-47940HIGHTYPO3 CMS Vulnerable to Privilege Escalation to System MaintainerEPSS 0.4%CVE-2025-12998HIGHBroken Authentication in extension “Modules” (modules)EPSS 0.4%CVE-2025-59022HIGHTYPO3 CMS Allows Broken Access Control in Recycler ModuleEPSS 0.4%