Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.48% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3… | |
| Aplazada | Alta (7.6) | 0.44% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by… | |
| Aplazada | Alta (7.2) | 0.41% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45,… | |
| Aplazada | Alta (7.6) | 0.24% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by… | |
| Aplazada | Media (5.1) | 0.44% | — | Typo3 Html-sanitizerAI | 8/6/2026 | 23/7/2026 | Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2. | |
| Aplazada | Baja (2.1) | 0.44% | — | Typo3 Html-sanitizerAI | 8/6/2026 | 23/7/2026 | When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer… | |
| Aplazada | Alta (7.1) | 0.50% | — | Typo3 CrawlerAI | 19/5/2026 | 17/6/2026 | The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure… | |
| Aplazada | Crítica (9.2) | 1.9% | 💥 Exploit | Typo3AI | 19/5/2026 | 17/6/2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content… | |
| Aplazada | Media (5.9) | 0.41% | — | Typo3AI | 19/5/2026 | 17/6/2026 | The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index. | |
| Analizada | Alta (7.3) | 0.27% | — | Typo3 | 21/4/2026 | 17/6/2026 | Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0. | |
| Aplazada | Media (5.2) | 0.14% | — | Typo3AI | 20/1/2026 | 17/6/2026 | The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for… | |
| Analizada | Media (5.2) | 0.19% | — | Typo3 | 13/1/2026 | 17/6/2026 | TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48,… | |
| Analizada | Alta (7.1) | 0.42% | — | Typo3 | 13/1/2026 | 17/6/2026 | Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavailable. This issue… | |
| Analizada | Media (5.3) | 0.27% | — | Typo3 | 13/1/2026 | 17/6/2026 | Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs – facilitating… | |
| Analizada | Media (5.3) | 0.32% | — | Typo3 | 13/1/2026 | 17/6/2026 | By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields. This… | |
| Aplazada | Alta (8.2) | 0.43% | — | Typo3 ModulesAI | 12/11/2025 | 17/6/2026 | Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5. | |
| Analizada | Media (5.3) | 0.24% | — | Typo3 | 9/9/2025 | 17/6/2026 | Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them. | |
| Analizada | Alta (7.1) | 0.29% | — | Typo3 | 9/9/2025 | 17/6/2026 | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access. | |
| Analizada | Media (5.3) | 0.30% | — | Typo3 | 9/9/2025 | 17/6/2026 | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules. | |
| Analizada | Media (5.3) | 0.24% | — | Typo3 | 9/9/2025 | 17/6/2026 | Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations. | |
| Analizada | Media (6.3) | 0.19% | — | Typo3 | 9/9/2025 | 17/6/2026 | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly. | |
| Analizada | Media (5.1) | 0.29% | — | Typo3 | 9/9/2025 | 17/6/2026 | An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the bookmark toolbar. | |
| Analizada | Media (5.3) | 0.18% | — | Typo3 | 9/9/2025 | 17/6/2026 | An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL. | |
| Aplazada | Alta (8.6) | 1.1% | — | Typo3 NS BackupAI | 2/9/2025 | 17/6/2026 | The ns_backup extension through 13.0.2 for TYPO3 allows command injection. | |
| Analizada | Media (5.3) | 0.21% | — | Typo3 | 22/7/2025 | 17/6/2026 | The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0 |