PatchSiren

TYPO3 CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM TYPO3 CVE published 2026-05-19

CVE-2026-46724

CVE-2026-46724 describes a path traversal weakness in a file indexer that fails to normalize its configured directory path. According to the NVD record, a backend user who already has permission to edit indexer configurations can use traversal sequences to point indexing at arbitrary locations on the server file system. The primary risk is unauthorized exposure of local files through the indexing workflow [truncated]

MEDIUM TYPO3 CVE published 2026-05-19

CVE-2026-46723

CVE-2026-46723 is a medium-severity information disclosure vulnerability in TYPO3's indexed search extension. The `additional_tables` configuration parameter in the page and tt_content indexers fails to validate table and field names, allowing a backend user with indexer configuration permissions to exfiltrate sensitive data from internal TYPO3 tables into the search index. Published on 2026-05-19, this i [truncated]

MEDIUM TYPO3 CVE published 2026-05-19

CVE-2026-46722

A medium-severity XML External Entity (XXE) vulnerability in the OOXML file indexer allows crafted .xlsx or .pptx documents to trigger local file disclosure or outbound HTTP requests, with retrieved content written to the search index. The vulnerability was published on 2026-05-19 and affects TYPO3 CMS based on the vendor security advisory reference. The CVSS 4.0 vector indicates network attack vector wit [truncated]

MEDIUM TYPO3 CVE published 2026-05-19

CVE-2026-46721

## Summary CVE-2026-46721 is a medium-severity authorization bypass vulnerability affecting TYPO3 CMS frontend user management. The create and edit flows fail to restrict which user properties may be submitted and do not enforce access control on frontend user group assignment. An attacker can exploit this by assigning arbitrary frontend user groups during account registration or modification, thereby gai [truncated]

HIGH Typo3 CVE published 2017-01-23

CVE-2016-5091

CVE-2016-5091 affects TYPO3 Extbase and is rated high severity by NVD. The issue can let a remote attacker obtain sensitive information and, in some cases, possibly execute arbitrary code through a crafted Extbase action. The source set shows the vendor and mailing-list references in May 2016, while the CVE record itself was published on 2017-01-23.

MEDIUM Typo3 CVE published 2017-01-23

CVE-2016-4056

CVE-2016-4056 is a cross-site scripting issue in the TYPO3 Backend component. The vulnerability affects TYPO3 6.2.x before 6.2.19 and can let a remote attacker inject arbitrary web script or HTML via the module parameter when creating a bookmark. Because the attack requires user interaction, the main risk is malicious code executing in an authenticated user’s browser session rather than direct server compromise.