« Volver al listado

Typo3

Typo3 CMS: vulnerabilidades y CVE

Typo3 CMS tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses11
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85400Alta (7.5)0.46%—8 sept 2026
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system…
CVE-2026-77132Media (5.3)0.43%—8 sept 2026
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about…
CVE-2026-15305Media (6.3)0.25%—14 jul 2026
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator…
CVE-2026-49742Alta (7.1)0.46%—9 jun 2026
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the…
CVE-2026-49741Alta (8.7)0.37%—9 jun 2026
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and…
CVE-2026-47352Media (5.3)0.41%—9 jun 2026
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue…
CVE-2026-47349Media (5.3)0.41%—9 jun 2026
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50,…
CVE-2026-47348Media (5.1)0.47%—9 jun 2026
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed…
CVE-2026-47346Alta (7.6)0.44%—9 jun 2026
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition…
CVE-2026-47343Alta (7.2)0.41%—9 jun 2026
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This…
CVE-2026-11607Alta (7.6)0.24%—9 jun 2026
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1078 Valid Accounts3
  3. T1005 Data from Local System1
  4. T1565 Data Manipulation1
  5. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Typo3