Executive brief
TYPO3 CMS is a popular open-source content management system used for building and managing websites. A security flaw in its search functionality allows authorized editors to inject malicious scripts into page titles. If a visitor views these titles in search results, the script could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the TYPO3 Indexed Search (indexed_search) extension. The root cause is a failure to sanitize page titles before they are stored in the search index and a subsequent failure to apply proper output encoding when these titles are rendered in frontend search results. An attacker with 'editor' privileges (Privileges Required: Low) can include HTML markup in page titles. When a victim performs a search that returns the malicious page title, the payload executes in the victim's browser context. This issue is fixed in TYPO3 versions 13.4.31 and 14.3.3.
Affected products
- TYPO3 TYPO3 CMS 13.0.0 to 13.4.30, 14.0.0 to 14.3.2
- TYPO3 Indexed Search (indexed_search) 13.0.0 to 13.4.30, 14.0.0 to 14.3.2
Timeline
- 2026-06-09: disclosed
- 2026-06-09: patched
- 2026-06-12: advisory
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-cg75-qfg2-w9hj
- https://github.com/TYPO3/typo3/commit/2e96dd0e9fab7ad877b741fb9f6fc645b4270a3e
- https://github.com/TYPO3/typo3/commit/8004b91a5951cfe01dda8554f77d0daa82d6b899
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47348.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-010