Where
-Infinity
0

Typo3 TYPO3TYPO3 Has Broken Authentication in Backend MFA

Risk 49
Severity
7.2
EPSS
0.09%
First published (updated )

Typo3 TYPO3TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer

Risk 49
Severity
7.2
EPSS
0.05%
First published (updated )

Typo3 TYPO3TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer

Risk 25
Severity
5.4
EPSS
0.02%
First published (updated )

Typo3 TYPO3TYPO3 Vulnerable to Unverified Password Change for Backend Users

Risk 20
Severity
3.8
EPSS
0.04%
First published (updated )

Typo3 TYPO3TYPO3 Vulnerable to Information Disclosure via DBAL Restriction Handling

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typo3 TYPO3TYPO3 Vulnerable to Server Side Request Forgery via Webhooks

Risk 21
Severity
4.4
EPSS
0.04%
First published (updated )

composer/typo3/cms-coreTYPO3 vulnerable to an HTML Injection in the History Module

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

composer/typo3/cms-corePath Traversal

Risk 41
Severity
5.5
First published (updated )

Typo3 TYPO3By-passing Cross-Site Scripting Protection in HTML Sanitizer

Risk 38
Severity
6.1
First published (updated )

composer/typo3/cms-installInformation Disclosure in Install Tool in typo3/cms-install

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/typo3/cms-coreWeak Authentication in Session Handling in typo3/cms-core

Risk 35
Severity
5.4
First published (updated )

composer/typo3/cms-coretypo3/cms-core Information Disclosure due to Out-of-scope Site Resolution

Risk 27
Severity
5.3
First published (updated )

Typo3 TYPO3Persisted Cross-Site Scripting in Frontend Rendering in typo3

Risk 64
Severity
8.8
First published (updated )

composer/typo3/cms-coreTYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration

Risk 46
Severity
5.7
First published (updated )

Typo3 TYPO3TYPO3 vulnerable to Arbitrary Code Execution via Form Framework

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typo3 TYPO3TYPO3 contains Insufficient Session Expiration after Password Reset

Risk 34
Severity
5.4
First published (updated )

Typo3 TYPO3TYPO3 vulnerable to Improper Authentication in Frontend Login

Risk 38
Severity
6.5
First published (updated )

Typo3 TYPO3TYPO3 subject to Uncontrolled Recursion resulting in Denial of Service

Risk 43
Severity
7.5
First published (updated )

Typo3 TYPO3Cross-Site Scripting in typo3/cms-core

Risk 46
Severity
6.5
First published (updated )

Typo3 TYPO3Stored Cross-Site Scripting via FileDumpController

Risk 46
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typo3 TYPO3Missing check for expiration time of password reset token in TYPO3

Risk 34
Severity
5.4
First published (updated )

Typo3 TYPO3User Enumeration via Response Timing in TYPO3

Risk 27
Severity
5.3
First published (updated )

composer/typo3/cmsDenial of Service via Page Error Handling in TYPO3/cms

Risk 43
Severity
7.5
First published (updated )

Typo3 TYPO3Insufficient Session Expiration in TYPO3 Admin Tool

Risk 66
Severity
7.2
First published (updated )

Typo3 TYPO3Cross-Site Scripting in Frontend Login Mailer

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typo3 TYPO3Cross-Site Scripting in Form Framework

Risk 34
Severity
5.4
First published (updated )

composer/typo3/cms-coreInsertion of Sensitive Information into Log File in typo3/cms-core

Risk 39
Severity
6.5
First published (updated )

Typo3 TYPO3Information Disclosure via Export Module in TYPO3 CMS

Risk 22
Severity
4.3
First published (updated )

composer/typo3/cmsCross-Site Scripting via Rich-Text Content

Risk 39
Severity
6.1
First published (updated )

composer/typo3/cms-coreInformation Disclosure in User Authentication

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203