These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2023-50462 is a vulnerability in the content_consent extension for TYPO3, allowing unauthenticated users to display various content elements, potentially exposing internal content elements through an insecure direct object reference (IDOR) issue. The vulnerability has a medium severity and affects TYPO3 installations using the content_consent extension version 2.0.1 or earlier. Defenders should priori [truncated]
The CVE-2023-50461 vulnerability was discovered in the Direct Mail extension for TYPO3, allowing an authenticated user to write to an arbitrary TSConfig page. This may lead to Configuration Injection and Arbitrary Code Execution. A valid backend user account with access to the Direct Mail Configuration backend module is needed to exploit this. The vulnerability's impact is significant as it can allow atta [truncated]
CVE-2023-50460 is a vulnerability in the femanager extension for TYPO3, allowing an authenticated backend user to perform actions on any frontend user. The CVE record was published on 2026-09-14T07:17:15.510Z. This vulnerability affects TYPO3 systems using the femanager extension. Defenders should assess exposure and prioritize verification of TYPO3 systems using the femanager extension. The vulnerability [truncated]
CVE-2023-50459 is a vulnerability in the femanager extension for TYPO3, allowing an authenticated frontend user to edit or delete data of various frontend users. The issue was discovered in versions 7.x before 7.2.3 and has been assigned a CVSS score of 5.4. The CVE record was published on 2026-09-14T07:17:15.353Z and last modified on 2026-09-22T20:00:03.713Z.
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. This CVE record was published on 2026-09-14T06:16:54.207Z and has not been modified since then. The NVD entry is currently Deferred. TYPO3 administrators and users with the femanager extension installed, especially those using the invitation component, should verify [truncated]
CVE-2026-85400 allows backend administrators without system maintainer privileges to schedule configuration commands, enabling them to modify arbitrary system configurations and potentially gain system maintainer privileges or cause a denial of service. This issue affects TYPO3 CMS versions 14.2.0-14.3.6 and requires an administrator-level backend user account to exploit.
Authenticated, low-privileged backend users can access unauthorized records and content elements due to missing authorization checks in several AJAX routes used for the backend localization wizard in TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34, and 14.0.0-14.3.6. This vulnerability allows unauthorized access, potentially leading to data exposure or leakage. Defenders [truncated]
CVE-2026-56095 is a high-severity vulnerability in a TYPO3 extension, with a CVSS score of 7.7. The extension's indexer insecurely uses PHP's unserialize() function when handling multi-value data for certain content object types, potentially exposing a PHP Object Injection surface if user-generated content can reach an indexed field. This vulnerability could allow attackers to inject malicious PHP objects [truncated]
CVE-2026-56094 allows a visitor to read public documents belonging to another site in a shared Solr core serving multiple TYPO3 sites. This issue arises from the extension's handling of the additionalFilters parameter, which can register a named siteHash filter before the system's own siteHash filter is applied. The query builder does not overwrite an already-registered named filter, enabling an attacker [truncated]
CVE-2026-56093 debrief based on CVE Program and NVD records. The vulnerability affects the Typo3 extension's frontend detail-view document lookup functionality, allowing unauthorized access to documents for visitors who can obtain or guess a valid Solr document ID. This medium-severity vulnerability requires defenders and administrators to assess exposure and verify access controls for siteHash and fronte [truncated]
CVE-2026-56092 allows anonymous visitors to bypass access restrictions on cached pages in Typo3 installations due to improper handling of page records by a vulnerable Typo3 extension. This vulnerability impacts Typo3 installations using the affected extension, requiring defenders to assess exposure and apply patches or updates to prevent exploitation. The vulnerability is caused by the extension's imprope [truncated]
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0, allowing requests from any script running on a TYPO3 instance's own domains to be accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This [truncated]
CVE-2026-15305 is a vulnerability in TYPO3 CMS that allows users to upload files with arbitrary MIME types. The issue affects TYPO3 CMS versions 14.2.0-14.3.4. This vulnerability has a CVSS score of 6.3 and is considered medium-severity. TYPO3 CMS administrators and users should review and update their installations to version 14.3.5 or later. The vulnerability is caused by the MimeTypeValidator being reg [truncated]
CVE-2026-49742 is a HIGH-severity vulnerability affecting TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, and 14.0.0-14.3.2. The issue allows backend users with file download permissions to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose [truncated]
CVE-2026-49741 is a high-severity vulnerability in TYPO3 CMS versions 14.0.0-14.3.3. Backend users with write access to the form_definition database table could directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. This allowed injecting arbitrary form configurations and re-enabling attack vectors originally [truncated]
CVE-2026-49740 is a PHP Object Injection vulnerability in TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry). The vulnerability allows an attacker with write access to the underlying storage backend (cache store or sys_registry database table) to inject a crafted serialized payload, potentially triggering PHP Object Injection. This could be exploited to achieve Remote Code [truncated]
A vulnerability in TYPO3 CMS, tracked as CVE-2026-49738, allows administrator users with access to the File Abstraction Layer to create new file storage definitions pointing to directories outside the project root. This is possible due to a flawed path allowance check in GeneralUtility::isAllowedAbsPath(), which performs a plain string prefix comparison without requiring a directory separator boundary. Th [truncated]
CVE-2026-47352 is a vulnerability in TYPO3 CMS that allows authenticated backend users to retrieve file metadata without proper permission checks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, and 14.0.0-14.3.3. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
CVE-2026-47351 is a medium-severity vulnerability in TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2. The issue allows backend users to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, potentially allowing users to gather information about records and files they are not authorized to view. The Common Vulnerability Scoring System (CVSS) score for this v [truncated]
A vulnerability in TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3 allows backend users to move records to a different page without having edit permissions on the source page. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity.
CVE-2026-47349 is a vulnerability in TYPO3 CMS that allows backend users with access to the Recycler module to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, and 14.0.0-14.3.3.
CVE-2026-47348 is a Cross-Site Scripting (XSS) vulnerability in TYPO3 CMS, a popular content management system. The vulnerability affects versions 13.0.0-13.4.30 and 14.0.0-14.3.2. Editors with access to create or modify page content could include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, t [truncated]
A medium-severity open redirect vulnerability, CVE-2026-47347, was found in TYPO3 CMS. The vulnerability occurs when applications use GeneralUtility::sanitizeLocalUrl to allow only local URLs, making them vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing atta [truncated]
CVE-2026-47346 is a high-severity vulnerability in TYPO3 CMS that allows backend users with file write permissions to upload malicious form definition files, potentially leading to arbitrary SQL statement execution and privilege escalation. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, and 14.0.0-14.3.2. The vulnerability has a CVSS score of 7.6 and [truncated]
CVE-2026-47343 is a high-severity vulnerability affecting TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2. The issue allows non-privileged backend users with file mount access to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictio [truncated]
CVE-2026-11607 is a high-severity vulnerability affecting TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, and 14.0.0-14.3.3. The issue allows backend users with access to the Form Framework to use files not ending in .form.yaml as form definitions, which are processed without denying the incorrect file extension. This can be exploited to execute arbitrary SQL statements, [truncated]
CVE-2026-47344 is a low-severity vulnerability in typo3/html-sanitizer that allows bypassing the cross-site scripting prevention mechanism. The vulnerability occurs when ALLOW_INSECURE_RAW_TEXT is enabled, and whitespace-variant closing tags are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This vulnerability was published o [truncated]
A SQL injection vulnerability exists in the AddressRepository::getSqlQuery() method of a TYPO3 extension. The method constructs database queries without proper input sanitization. While the vulnerable method is not invoked within the extension itself—eliminating direct risk in default installations—custom extensions that call this method with untrusted input can expose sites to SQL injection attacks. The [truncated]
CVE-2026-8726 is a high-severity SQL injection vulnerability in a TYPO3 extension, published 2026-05-19. The flaw stems from improper sanitization of user input before use in database queries. An unauthenticated attacker can inject arbitrary SQL via a URL parameter on pages utilizing the 'Date Menu of news articles' plugin. Exploitation is contingent on two conditions: the plugin must be active, and the T [truncated]
CVE-2026-46725 describes a critical PHP object injection issue in a TYPO3-related extension. An attacker can supply a crafted cookie that is passed directly into PHP unserialize() without safe handling. If the affected content element is configured with Persistent Mode: Static, a remote unauthenticated attacker may be able to trigger code execution on the TYPO3 server. The vulnerability is rated CVSS 9.2 [truncated]