Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.28% | — | Typo3 PowermailAI | 22/7/2025 | 17/6/2026 | The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0 | |
| Aplazada | Alta (8.6) | 0.35% | — | Reint DownloadmanagerAITypo3AI | 21/5/2025 | 17/6/2026 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. | |
| Aplazada | Alta (8.6) | 0.35% | — | Typo3AIStanislas Rolland SR Feuser RegisterAI | 21/5/2025 | 17/6/2026 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. | |
| Aplazada | Media (6.8) | 0.75% | — | Typo3 NS BackupAI | 21/5/2025 | 17/6/2026 | The ns_backup extension through 13.0.0 for TYPO3 allows command injection. | |
| Aplazada | Media (5.3) | 0.28% | — | Typo3AIIn2code FemanagerAI | 21/5/2025 | 17/6/2026 | The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference. | |
| Aplazada | Alta (8.6) | 0.35% | — | Typo3 NS BackupAI | 21/5/2025 | 17/6/2026 | The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. | |
| Analizada | Alta (7.2) | 0.45% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient enforcement of access restrictions on all backend… | |
| Analizada | Alta (7.2) | 0.44% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting… | |
| Analizada | Media (5.4) | 0.17% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction means it is possible… | |
| Analizada | Baja (3.8) | 0.26% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current password. When an administrator updates… | |
| Analizada | Media (5.3) | 0.29% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction layer (DBAL), frontend user permissions… | |
| Analizada | Media (4.4) | 0.26% | — | Typo3 | 20/5/2025 | 17/6/2026 | TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, Webhooks are inherently vulnerable to Cross-Site Request Forgery (CSRF), which can be exploited by adversaries to target internal resources (e.g., localhost or… | |
| Aplazada | Media (4.2) | 0.18% | — | Typo3 OidcAI | 16/3/2025 | 17/6/2026 | An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements are met: (1) an attacker can anticipate the e-mail address of… | |
| Analizada | Media (6.5) | 0.23% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Alta (8) | 0.26% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (4.3) | 0.19% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (5.4) | 0.19% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Alta (8.8) | 0.36% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (4.3) | 0.19% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (5.4) | 0.24% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (4.3) | 0.24% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components… | |
| Analizada | Media (6.1) | 0.24% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation… | |
| Analizada | Media (5.3) | 0.32% | — | Typo3 | 14/1/2025 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the problem described. There… | |
| Analizada | Media (4.9) | 0.71% | — | Typo3 | 28/10/2024 | 17/6/2026 | TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1. | |
| Analizada | Media (4.3) | 0.30% | — | Typo3 | 8/10/2024 | 17/6/2026 | TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not… |