Skip to content
RequestGuard Vulnerabilities
Pricing

CVE record

CVE-2026-47349

TYPO3 CMS - Broken Access Control in Recycler

Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

CVE evidence

Known exploitation

Not listed in fetched KEV catalog

Absence from the fetched catalog does not establish that exploitation has not occurred.

Severity

moderate

CVSS 5.3 ยท CVSS_V4

Affected packages

2

Supported package records returned by OSV. Vendor and product names are not used to infer matches.

OSV package mapping

Affected open-source packages

PackageEcosystemFixed versions
typo3/cms-corecomposer10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3
typo3/cms-recyclercomposer10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3