Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.27% | — | Typo3 Content ConsentAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference… | |
| Aplazada | Alta (8.8) | 0.33% | — | Typo3AITypo3 Direct MailAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4… | |
| Aplazada | Media (5.4) | 0.24% | — | Typo3 FemanagerAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. | |
| Aplazada | Media (5.4) | 0.42% | — | Typo3 FemanagerAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | |
| Aplazada | Media (4.2) | 0.14% | — | Typo3AIIn2code FemanagerAI | 14/9/2026 | 22/9/2026 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. | |
| Aplazada | Alta (7.5) | 0.46% | — | Typo3 CMSAI | 8/9/2026 | 8/9/2026 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for… | |
| Aplazada | Media (5.3) | 0.43% | — | Typo3 CMSAI | 8/9/2026 | 8/9/2026 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability… | |
| Aplazada | Baja (2.1) | 0.49% | — | TyporaAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading… | |
| Aplazada | Media (5.3) | 0.24% | — | OpensslAITypo3AI | 25/8/2026 | 26/8/2026 | When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | |
| Aplazada | Alta (7.7) | 0.40% | — | Typo3AITypo3 Event RegistrationAI | 25/8/2026 | 26/8/2026 | The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects.… | |
| Aplazada | Media (6) | 0.35% | — | Typo3AI | 25/8/2026 | 26/8/2026 | The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses the current database value of the… | |
| Aplazada | Alta (7.7) | 0.32% | — | Typo3AI | 25/8/2026 | 17/9/2026 | The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3… | |
| Aplazada | Media (6.3) | 0.33% | — | Apache SolrAITypo3AI | 25/8/2026 | 17/9/2026 | The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read… | |
| Aplazada | Alta (7.6) | 0.29% | — | Typo3AI | 25/8/2026 | 17/9/2026 | The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Typo3AI | 25/8/2026 | 28/9/2026 | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. | |
| Aplazada | Alta (7.3) | 0.24% | — | Typo3 CMSAI | 11/8/2026 | 26/8/2026 | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or… | |
| Aplazada | Media (6.3) | 0.25% | — | Typo3 CMSAI | 14/7/2026 | 3/9/2026 | Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form definition properties were applied, resulting… | |
| Aplazada | Alta (7.1) | 0.46% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3… | |
| Aplazada | Alta (8.7) | 0.37% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. This allowed injecting arbitrary form configurations, re-enabling attack vectors… | |
| Aplazada | Media (6.3) | 0.59% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could inject a crafted serialized payload to… | |
| Aplazada | Baja (2.1) | 0.52% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to… | |
| Aplazada | Media (5.3) | 0.41% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and… | |
| Aplazada | Media (5.3) | 0.41% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2. | |
| Aplazada | Media (5.3) | 0.41% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2. | |
| Aplazada | Media (5.3) | 0.41% | — | Typo3 CMSAI | 9/6/2026 | 23/7/2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2. |