Skip to content
RequestGuard Vulnerabilities
Pricing

typo3/cms-core

TYPO3 CMS Core

Composer latest 13.4.35 GPL-2.0-or-later

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

13.4.35

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

130 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

130

TYPO3 CMS Insecure Deserialization & Arbitrary Code Execution

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.17ECOSYSTEM: introduced 9.0.0; fixed 9.3.2ECOSYSTEM: introduced 7.0.0; fixed 7.6.30>=8.0.0,<8.7.23|>=9.0.0,<9.5.4

Fixed versions: 8.7.17, 9.3.2, 7.6.30

TYPO3 CMS has Broken Access Control in its Form Framework

Affected range

ECOSYSTEM: introduced 0; fixed 10.4.57ECOSYSTEM: introduced 11.0.0; fixed 11.5.51ECOSYSTEM: introduced 12.0.0; fixed 12.4.46ECOSYSTEM: introduced 13.0.0; fixed 13.4.31ECOSYSTEM: introduced 14.0.0; fixed 14.3.3

Fixed versions: 10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3

TYPO3 CMS has Broken Access Control in its Media Module

Affected range

ECOSYSTEM: introduced 11.0.0; fixed 11.5.51ECOSYSTEM: introduced 12.0.0; fixed 12.4.46ECOSYSTEM: introduced 13.0.0; fixed 13.4.31ECOSYSTEM: introduced 14.0.0; fixed 14.3.3>=11.0.0,<11.5.51|>=12.0.0,<12.4.46|>=13.0.0,<13.4.31|>=14.0.0,<14.3.3

Fixed versions: 11.5.51, 12.4.46, 13.4.31, 14.3.3

TYPO3 CMS: Destructive Actions on File Mount Folders

Affected range

ECOSYSTEM: introduced 0; fixed 10.4.57ECOSYSTEM: introduced 11.0.0; fixed 11.5.51ECOSYSTEM: introduced 12.0.0; fixed 12.4.46ECOSYSTEM: introduced 13.0.0; fixed 13.4.31ECOSYSTEM: introduced 14.0.0; fixed 14.3.3

Fixed versions: 10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3

TYPO3 CMS has Broken Access Control in its Form Framework

Affected range

ECOSYSTEM: introduced 0; fixed 10.4.57ECOSYSTEM: introduced 11.0.0; fixed 11.5.51ECOSYSTEM: introduced 12.0.0; fixed 12.4.46ECOSYSTEM: introduced 13.0.0; fixed 13.4.31ECOSYSTEM: introduced 14.0.0; fixed 14.3.3

Fixed versions: 10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3

TYPO3 vulnerable to Improper Access Control Persisting File Abstraction Layer Entities via Data Handler

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.57ECOSYSTEM: introduced 9.0.0; fixed 9.5.46ECOSYSTEM: introduced 10.0.0; fixed 10.4.43ECOSYSTEM: introduced 11.0.0; fixed 11.5.35ECOSYSTEM: introduced 12.0.0; fixed 12.4.11

Fixed versions: 8.7.57, 9.5.46, 10.4.43, 11.5.35, 12.4.11, 13.0.1

TYPO3 is vulnerable to Cross-Site Scripting via frontend rendering

Affected range

ECOSYSTEM: introduced 12.0.0; fixed 12.2.0ECOSYSTEM: introduced 11.0.0; fixed 11.5.23ECOSYSTEM: introduced 10.0.0; fixed 10.4.36ECOSYSTEM: introduced 9.0.0; fixed 9.5.40ECOSYSTEM: introduced 8.7.0; fixed 8.7.51

Fixed versions: 12.2.0, 11.5.23, 10.4.36, 9.5.40, 8.7.51

Insecure Deserialization in Backend User Settings in TYPO3 CMS

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.17ECOSYSTEM: introduced 10.0.0; fixed 10.4.2>=10.0.0,<10.4.2|>=9.0.0,<9.5.17

Fixed versions: 9.5.17, 10.4.2

Class destructors causing side-effects when being unserialized in TYPO3 CMS

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.17ECOSYSTEM: introduced 10.0.0; fixed 10.4.2>=10.0.0,<10.4.2|>=9.0.0,<9.5.17

Fixed versions: 9.5.17, 10.4.2

Unrestricted File Upload in Form Framework

Affected range

ECOSYSTEM: introduced 10.0.0; fixed 10.4.14ECOSYSTEM: introduced 11.0.0; fixed 11.1.1ECOSYSTEM: introduced 9.0.0; fixed 9.5.25>=10.0.0,<10.4.14|>=11.0.0,<11.1.1|>=9.0.0,<9.5.25

Fixed versions: 10.4.14, 11.1.1, 9.5.25

Broken Access Control in Form Framework

Affected range

ECOSYSTEM: introduced 10.0.0; fixed 10.4.14ECOSYSTEM: introduced 11.0.0; fixed 11.1.1ECOSYSTEM: introduced 9.0.0; fixed 9.5.25>=10.0.0,<10.4.14|>=11.0.0,<11.1.1|>=9.0.0,<9.5.25

Fixed versions: 10.4.14, 11.1.1, 9.5.25

TYPO3 Install Tool vulnerable to Code Execution

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.57ECOSYSTEM: introduced 9.0.0; fixed 9.5.46ECOSYSTEM: introduced 10.0.0; fixed 10.4.43ECOSYSTEM: introduced 11.0.0; fixed 11.5.35ECOSYSTEM: introduced 12.0.0; fixed 12.4.11

Fixed versions: 8.7.57, 9.5.46, 10.4.43, 11.5.35, 12.4.11, 13.0.1

Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.20ECOSYSTEM: introduced 10.0.0; fixed 10.4.6>=10.0.0,<10.4.6|>=9.0.0,<9.5.20

Fixed versions: 9.5.20, 10.4.6

Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.20ECOSYSTEM: introduced 10.0.0; fixed 10.4.6>=10.0.0,<10.4.6|>=9.0.0,<9.5.20

Fixed versions: 9.5.20, 10.4.6

Backend Same-Site Request Forgery in TYPO3 CMS

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.17ECOSYSTEM: introduced 10.0.0; fixed 10.4.2>=10.0.0,<10.4.2|>=9.0.0,<9.5.17

Fixed versions: 9.5.17, 10.4.2

Cleartext storage of session identifier

Affected range

ECOSYSTEM: introduced 9.0.0; fixed 9.5.23ECOSYSTEM: introduced 10.0.0; fixed 10.4.10ECOSYSTEM: introduced 8.7.0; fixed 8.7.38>=10.0.0,<10.4.10|>=9.0.0,<9.5.23|>=8.7.0,<8.7.38

Fixed versions: 9.5.23, 10.4.10, 8.7.38

TYPO3 Vulnerable to Insecure Deserialization

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.27ECOSYSTEM: introduced 9.0.0; fixed 9.5.8>=8.0.0,<8.7.27|>=9.0.0,<9.5.8

Fixed versions: 8.7.27, 9.5.8

TYPO3 Allows Privilege Escalation to System Maintainer

Affected range

ECOSYSTEM: introduced 10.4.0; fixed 10.4.50ECOSYSTEM: introduced 11.0.0; fixed 11.5.44ECOSYSTEM: introduced 12.0.0; fixed 12.4.31ECOSYSTEM: introduced 13.0.0; fixed 13.4.12>=13.0.0,<=13.4.11|>=12.0.0,<=12.4.30|>=11.0.0,<=11.5.43|>=10.4.0,<=10.4.49

Fixed versions: 10.4.50, 11.5.44, 12.4.31, 13.4.12

TYPO3 Possible Insecure Deserialization in Extbase Request Handling

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.30ECOSYSTEM: introduced 9.0.0; fixed 9.5.12>=8.0.0,<8.7.27|>=9.0.0,<9.5.8

Fixed versions: 8.7.30, 9.5.12

TYPO3 Arbitrary Code Execution and Cross-Site Scripting in Backend API

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.27ECOSYSTEM: introduced 9.0.0; fixed 9.5.8>=8.0.0,<8.7.21|>=9.0.0,<9.5.2

Fixed versions: 8.7.27, 9.5.8

TYPO3 Security Misconfiguration in Frontend Session Handling

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.7.27ECOSYSTEM: introduced 9.0.0; fixed 9.5.8>=10.0.0,<10.2.1|>=8.0.0,<8.7.30|>=9.0.0,<9.5.12

Fixed versions: 8.7.27, 9.5.8

TYPO3 CMS Privilege Escalation and SQL Injection

Affected range

ECOSYSTEM: introduced 8.5.0; fixed 8.7.17ECOSYSTEM: introduced 9.0.0; fixed 9.3.2>=8.0.0,<8.7.27|>=9.0.0,<9.5.8

Fixed versions: 8.7.17, 9.3.2

Show 75 more advisories
GHSA-x4rj-f7m6-42c3 TYPO3 CMS Authentication Bypass vulnerability
GHSA-ppvg-hw62-6ph9 TYPO3 Security Misconfiguration in Install Tool Cookie
GHSA-96jg-pmc4-cx39 TYPO3 CMS Insecure Deserialization
GHSA-f9hr-7cfq-mjg2 TYPO3 Arbitrary Code Execution via File List Module
GHSA-hjx5-v9xg-7h25 TYPO3 Denial of Service in Frontend Record Registration
GHSA-rxc9-f2x6-qh4w TYPO3 Security Misconfiguration for Backend User Accounts
GHSA-rcgc-4xfc-564v TYPO3 Insecure Deserialization in Query Generator & Query View
GHSA-w2fr-65vp-mxw3 Deserialization of untrusted data in Symfony
GHSA-3w4h-r27h-4r2w TYPO3 Image Processing susceptible to Code Execution
GHSA-c5wx-6c2c-f7rm TYPO3 CMS vulnerable to Arbitrary Code Execution via Form Framework
GHSA-m64j-j252-jxmr TYPO3 SQL injection vulnerability in the Extbase Framework
GHSA-q93m-25xv-94hh TYPO3 CMS: Broken Access Control in Media Module
GHSA-c78m-c52x-jgwp TYPO3 CMS has Insecure Deserialization via Core API
GHSA-cg75-qfg2-w9hj TYPO3 CMS has Cross-Site Scripting in Indexed Search
GHSA-2j54-93q2-3hjq TYPO3 CMS has Broken Access Control in Backend API
GHSA-3p42-w5ch-gg42 TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
GHSA-qcmw-6rm2-5x78 TYPO3 CMS has Broken Access Control in its DataHandler
GHSA-f34x-rx2w-7pm3 TYPO3 CMS has Broken Access Control in the Recycler Module
GHSA-v6mw-h7w6-59w3 TYPO3 vulnerable to Cross-Site Scripting in the Form Manager Module
GHSA-hw6c-6gwq-3m3m TYPO3 vulnerable to Cross-Site Scripting in the ShowImageController
GHSA-36g8-62qv-5957 TYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageController
GHSA-h47m-3f78-qp9g TYPO3 Install Tool vulnerable to Information Disclosure of Encryption Key
GHSA-38r2-5695-334w TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed Passwords
GHSA-3vmm-7h4j-69rm TYPO3 vulnerable to Weak Authentication in Session Handling
GHSA-wf85-8hx9-gj7c TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI Scheme
GHSA-rgcg-28xm-8mmw Cross-Site Scripting in Backend Grid View
GHSA-vqqx-jw6p-q3rf Cross-Site Scripting in Fluid view helpers
GHSA-7733-hjv6-4h47 Cross-Site Scripting in ternary conditional operator
GHSA-8mq9-fqv8-59wf Cross-Site Scripting in Page Preview
GHSA-c5c9-8c6m-727v Cross-Site Scripting via Rich-Text Content
GHSA-qx3w-4864-94ch Cleartext storage of session identifier
GHSA-x79j-wgqv-g8h2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form
GHSA-m2jh-fxw4-gphm HTTP Host Header Injection
GHSA-4jhw-2p6j-5wmp Open Redirection in Login Handling
GHSA-6mh3-j5r5-2379 Cross-Site Scripting in Query Generator & Query View
GHSA-fjh3-g8gq-9q92 Cross-Site Scripting in Content Preview
GHSA-x7hc-x7fm-f7qh Cross-Site Scripting in Content Preview (CType menu)
GHSA-4p9g-qgx9-397p Denial of Service in Page Error Handling
GHSA-34fr-fhqr-7235 Information Disclosure in User Authentication
GHSA-4j77-gg36-9864 Cross-Site Scripting in TYPO3 CMS Link Handling
GHSA-43gj-mj2w-wh46 Cross-Site Scripting in TYPO3 CMS Form Engine
GHSA-7vp9-x248-9vr9 TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool
GHSA-pj7m-g53m-7638 Bootstrap Cross-site Scripting vulnerability
GHSA-p5jq-5383-qvc7 TYPO3 CMS uses insufficient entropy when generating passwords
GHSA-cvm2-5f78-g9m8 TYPO3 CMS exposes sensitive information in an error message
GHSA-72jf-5fg5-3cw3 TYPO3 CMS has an open‑redirect vulnerability
GHSA-9hq9-cr36-4wpj TYPO3 Allows Unrestricted File Upload in File Abstraction Layer
GHSA-2fx5-pggv-6jjr TYPO3 Potential Open Redirect via Parsing Differences
GHSA-59pj-7mjh-4465 TYPO3 SQL Injection in low-level Query Generator
GHSA-95qm-3xp7-vfj5 TYPO3 Cross-Site Scripting in Form Framework validation handling
GHSA-gqqf-g5r7-84vf TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
GHSA-xmgr-jff3-fcfv TYPO3 Security Misconfiguration in User Session Handling
GHSA-4459-qrcc-vfcf TYPO3 Cross-Site Scripting in Form Framework
GHSA-8c25-vj2w-p72j TYPO3 Cross-Site Scripting in Frontend User Login
GHSA-wvvp-jwf5-qcpc TYPO3 Information Disclosure in Page Tree
GHSA-g776-759r-pf6x TYPO3 Broken Access Control in Import Module
GHSA-wg8h-gxf4-g4gh TYPO3 Cross-Site Scripting in Online Media Asset Rendering
GHSA-g4c9-qfvw-fmr4 TYPO3 Cross-Site Scripting in Backend Modal Component
GHSA-wj85-rg5g-v8jm TYPO3 Information Disclosure in User Authentication
GHSA-29m4-mx89-3mjg TYPO3 Denial of Service in Online Media Asset Handling
GHSA-4ppr-jw47-9qm5 TYPO3 Cross-Site Scripting in Link Handling
GHSA-9rx9-7fmh-gj3g TYPO3 Broken Access Control in Localization Handling
GHSA-66c2-7g4p-wx4p TYPO3 Information Disclosure in Install Tool
GHSA-p2h4-7fp3-cmh8 TYPO3 Disclosure of Information about Installed Extensions
GHSA-76r3-m635-p3vc TYPO3 Cross-Site Scripting in Language Pack Handling
GHSA-rv8r-8mh5-5376 TYPO3 Information Disclosure in Backend User Interface
GHSA-6xwf-7rfm-4gwc TYPO3 Cross-Site Scripting in Filelist Module
GHSA-8w3p-qh3x-6gjr TYPO3 CMS vulnerable to Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
GHSA-77p4-wfr8-977w TYPO3 Directory Traversal on ZIP extraction
GHSA-w6x2-jg8h-p6mp Path Traversal in TYPO3 File Abstraction Layer Storages
GHSA-r6fv-56gp-j3r4 Typo3 Cross-Site Scripting in Link Handling
GHSA-fh99-4pgr-8j99 Insertion of Sensitive Information into Log File in typo3/cms-core
GHSA-g68x-vvqq-pvw3 Ckeditor XSS Vulnerability
GHSA-f35p-hcwf-9f9f TYPO3 Unrestricted File Upload vulnerability
GHSA-m7rg-85g8-28m9 TYPO3 API function vulnerable to Cross-site Scripting