Vulnerabilidades em typo3
175 resultadosAnálise Vexday
TYPO3 apresenta exposição mínima com apenas 1 CVE registrada na base, sem incidentes de exploração ativa (KEV) ou vulnerabilidades críticas. A fraqueza identificada é XSS (CWE-79), com risco não recente, mantendo o fornecedor em postura de baixo risco operacional no curto prazo.
CVE-2026-47350MEDIUMTYPO3 CMS - Broken Access Control in DataHandlerEPSS 0.2%CVE-2026-11607HIGHTYPO3 CMS - Broken Access Control in Form FrameworkEPSS 0.2%CVE-2023-50459MEDIUMAn issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user componEPSS 0.2%CVE-2026-47352MEDIUMTYPO3 CMS - Broken Access Control in Backend APIEPSS 0.2%CVE-2026-47351MEDIUMTYPO3 CMS - Broken Access Control in ClipboardEPSS 0.2%CVE-2023-50460MEDIUMAn issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to peEPSS 0.2%CVE-2026-47343HIGHTYPO3 CMS - Destructive Actions on File Mount FoldersEPSS 0.2%CVE-2026-77137HIGHSQL Injection in extension "Forms Export" (frp_form_answers)EPSS 0.2%CVE-2026-77129HIGHServer-Side Template Injection in extension "Event management and registration" (sf_event_mgt)EPSS 0.2%CVE-2025-48206MEDIUMThe ns_backup extension through 13.0.0 for TYPO3 allows XSS.EPSS 0.2%CVE-2025-59016MEDIUMInformation Disclosure via File Abstraction LayerEPSS 0.2%CVE-2025-48203MEDIUMThe cs_seo extension through 9.2.0 for TYPO3 allows XSS.EPSS 0.2%CVE-2025-59019MEDIUMInformation Disclosure via CSV DownloadEPSS 0.2%CVE-2024-55945MEDIUMCross-Site Request Forgery in DB Check Module in TYPO3EPSS 0.2%CVE-2026-56092HIGHBroken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)EPSS 0.2%CVE-2026-1323MEDIUMInsecure Deserialization in extension "Mailqueue" (mailqueue)EPSS 0.2%CVE-2026-49740MEDIUMTYPO3 CMS - Insecure Deserialization in Core APIEPSS 0.2%CVE-2025-7900MEDIUMInsecure Direct Object Reference in extension "femanager" (femanager)EPSS 0.2%CVE-2026-19418HIGHTYPO3 CMS - Broken Access Control in Backend and Install ToolEPSS 0.2%CVE-2026-77145HIGHBroken Access Control in extension "Events 2" (events2)EPSS 0.2%