Typo3
Typo3 CMS: vulnerabilidades y CVE
Typo3 CMS tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses11
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85400 | Alta (7.5) | 0.46% | — | 8 sept 2026 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system… |
| CVE-2026-77132 | Media (5.3) | 0.43% | — | 8 sept 2026 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about… |
| CVE-2026-15305 | Media (6.3) | 0.25% | — | 14 jul 2026 | Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator… |
| CVE-2026-49742 | Alta (7.1) | 0.46% | — | 9 jun 2026 | Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the… |
| CVE-2026-49741 | Alta (8.7) | 0.37% | — | 9 jun 2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and… |
| CVE-2026-47352 | Media (5.3) | 0.41% | — | 9 jun 2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue… |
| CVE-2026-47349 | Media (5.3) | 0.41% | — | 9 jun 2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50,… |
| CVE-2026-47348 | Media (5.1) | 0.47% | — | 9 jun 2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed… |
| CVE-2026-47346 | Alta (7.6) | 0.44% | — | 9 jun 2026 | Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition… |
| CVE-2026-47343 | Alta (7.2) | 0.41% | — | 9 jun 2026 | Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This… |
| CVE-2026-11607 | Alta (7.6) | 0.24% | — | 9 jun 2026 | Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.