« Volver al listado

Typo3

Typo3: vulnerabilidades y CVE

Typo3 tiene 234 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE234
Últimos 12 meses17
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-50461Alta (8.8)0.33%—14 sept 2026
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for…
CVE-2023-45023Media (4.2)0.14%—14 sept 2026
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
CVE-2026-77131Media (5.3)0.24%—25 ago 2026
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API…
CVE-2026-77129Alta (7.7)0.40%—25 ago 2026
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid…
CVE-2026-77127Media (6)0.35%—25 ago 2026
The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and…
CVE-2026-56095Alta (7.7)0.32%—25 ago 2026
The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and…
CVE-2026-56094Media (6.3)0.33%—25 ago 2026
The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered…
CVE-2026-56092Alta (7.6)0.29%—25 ago 2026
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous…
CVE-2026-77138Crítica (9.3)0.72%—25 ago 2026
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP…
CVE-2026-46725Crítica (9.2)1.9%—19 may 2026
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object…
CVE-2026-46723Media (5.9)0.41%—19 may 2026
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3…
CVE-2026-6553Alta (7.3)0.27%—21 abr 2026
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
CVE-2026-0895Media (5.2)0.14%—20 ene 2026
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is…
CVE-2026-0859Media (5.2)0.19%—13 ene 2026
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code…
CVE-2025-59022Alta (7.1)0.42%—13 ene 2026
Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to…
CVE-2025-59021Media (5.3)0.27%—13 ene 2026
Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts.…
CVE-2025-59020Media (5.3)0.32%—13 ene 2026
By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a…
CVE-2025-59019Media (5.3)0.24%—9 sept 2025
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within…
CVE-2025-59018Alta (7.1)0.29%—9 sept 2025
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX…
CVE-2025-59017Media (5.3)0.30%—9 sept 2025
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes…
CVE-2025-59016Media (5.3)0.24%—9 sept 2025
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full…
CVE-2025-59015Media (6.3)0.19%—9 sept 2025
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.
CVE-2025-59014Media (5.1)0.29%—9 sept 2025
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user…
CVE-2025-59013Media (5.3)0.18%—9 sept 2025
An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external…
CVE-2025-7900Media (5.3)0.21%—22 jul 2025
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
CVE-2025-48207Alta (8.6)0.35%—21 may 2025
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48205Alta (8.6)0.35%—21 may 2025
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48202Media (5.3)0.28%—21 may 2025
The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-47941Alta (7.2)0.45%—20 may 2025
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during…
CVE-2025-47940Alta (7.2)0.44%—20 may 2025
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services8
  2. T1059 Command and Scripting Interpreter5
  3. T1190 Exploit Public-Facing Application4
  4. T1005 Data from Local System3
  5. T1078 Valid Accounts3
  6. T1203 Exploitation for Client Execution3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Typo3